CVE-2026-25544Disclosure(payloadcms / payload)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch payloadcms payload systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Payload is a free and open source headless content management system. Prior to 3.73.0, when querying JSON or richText fields, user input was directly embedded into SQL without escaping, enabling blind SQL injection attacks. An unauthenticated attacker could extract sensitive data (emails, password reset tokens) and achieve full account takeover without password cracking. This vulnerability is fixed in 3.73.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • payload

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • Peaked 3d ago at 4 mentions (2026-02-06); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
payload

Deep dive

Activity timeline7 mentions / 4d
01234Mentions · 2026-02-06: 4Mentions · 2026-02-07: 1Mentions · 2026-02-10: 1Mentions · 2026-03-18: 1Patch / Workaround · 2026-02-06: 2Patch / Workaround · 2026-02-07: 1Technical Details · 2026-02-06: 4Technical Details · 2026-02-07: 1Technical Details · 2026-02-10: 1Technical Details · 2026-03-18: 102-0602-0702-1003-18
Signal classification2 categories
Disclosure
457.1%
Patch
342.9%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-064
Disclosure2Patch2
2026-02-071
Patch1
2026-02-101
Disclosure1
2026-03-181
Disclosure1
Full discourse7 posts
  • Komodo Cyber Security@Komodosec
    Disclosure

    #VulnerabilityReport #blindsqli CVE-2026-25544: Critical Payload CMS SQLi (CVSS 9.8) Exposes Admin Tokens https://securityonline.info/cve-2026-25544-critical-payload-cms-sqli-cvss-9-8-exposes-admin-tokens/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The tweet announces CVE-2026-25544 as a critical blind SQL injection flaw that exposes admin tokens, providing basic technical details and a reference link for more information.

    0001068
    1.5K followersView on X
  • Karma-X@Karma_X_Inc
    Disclosure

    CVE-2026-25544: Critical Payload CMS SQLi (CVSS 9.8) Exposes Admin Tokens https://securityonline.info/cve-2026-25544-critical-payload-cms-sqli-cvss-9-8-exposes-admin-tokens/

    Post summary

    The text announces CVE-2026-25544, a high‑severity SQL injection in Payload CMS that exposes admin tokens, with a CVSS score of 9.8.

    0000061
    73 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: CVE-2026-25544 in Payload CMS (<3.73.0) allows unauthenticated SQL injection — attackers can steal emails & tokens, risking full account takeover. Patch now! https://radar.offseq.com/threat/cve-2026-25544-cwe-89-improper-neutralization-of-s-972c134b #OffSeq #Payloa... https://t.co/w9b4levAWF

    Post summary

    The tweet announces CVE‑2026‑25544 as a critical unauthenticated SQL injection in Payload CMS, warns of data exfiltration risk, and urges users to apply the patch.

    0000077
    268 followersView on X
  • Säkerhetsbloggen@Sakerhetsblogg
    Patch

    CVE-2026-25544 i Payload CMS gör att angripare kan utföra blind SQL injection och ta över användarkonton utan lösenord. Uppgradera till 3.73.0 omedelbart för att skydda dig! #säkerhet #cybersäkerhet #CVE

    Post summary

    The post highlights that CVE-2026-25544 in Payload CMS enables blind SQL injection to hijack accounts, and urges users to upgrade immediately to version 3.73.0 for protection.

    0000056
    7 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25544 Payload is a free and open source headless content management system. Prior to 3.73.0, when querying JSON or richText fields, user input was directly embedded into SQ… https://www.cve.org/CVERecord?id=CVE-2026-25544

    Post summary

    The passage announces a SQL injection flaw in a free and open source headless CMS affecting versions prior to 3.73.0.

    00000205
    56.5K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-25544: Payload has an SQL Injection in ... Unauthenticated blind SQLi in PayloadCMS JSON/RichText queries enables full account takeover via direct extraction of e... https://zerodaysignal.com/vulnerability/CVE-2026-25544 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2026‑25544, an unauthenticated blind SQL injection in PayloadCMS’s JSON/RichText queries capable of full account takeover, but it does not provide a PoC, exploit code, patch, or evidence of active exploitation.

    0000089
    132 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    Payload Drizzle users: A SQL Injection flaw (CVE-2026-25544) affects JSON/RichText queries on PostgreSQL/SQLite. Apply available updates. #SQLi #PayloadCMS #infosec https://www.pulsepatch.io/posts/cve-2026-25544-payload-drizzle-sql-injection

    Post summary

    CVE‑2026‑25544 is a SQL injection vulnerability in Payload Drizzle affecting JSON/RichText queries; users are advised to apply the available updates.

    0000059
    1 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppayloadcmspayload-node.js-

Explore more