
🚨Critical - Payload CMS SQL Injection via Dynamic Filters/Joins (CVE-2026-105845) Payload headless CMS SQL injection in the SQLite and Postgres adapters when building queries from dynamic filters/joins on readable collections. Untrusted users can craft filter/join params to inject SQL, enabling data exfiltration and DB tampering. Other adapters are not affected. 👉Affected: payload < 3.88.0 | Upgrade to 3.88.0
