Payload CMS gets 15 security advisories in a day, three critical, including SQL injection
The GitHub Advisory Database published 15 reviewed advisories for Payload, the TypeScript headless CMS, and its plugins on 6 October: three rated critical, seven high and five medium.

The three critical ones.
- SQL injection on SQLite and Postgres (GHSA-v49j-62m6-pgrr, CVE-2026-105845). Exploitable when untrusted users can query readable collections with dynamic filters or joins. Affects
payload3.0.0 to before 3.88.0; fixed in 3.88.0 and 4.0.0-canary.27. Sites on MongoDB (@payloadcms/mongodb) are not affected. Until upgrading, the advisory suggests stopping untrusted users from supplying dynamic filters or join parameters and limiting read access. - Prototype pollution in the Import Export plugin (GHSA-qf28-8hc6-vwrp, CVE-2026-105844). An unauthenticated user could cause behaviour that the advisory says allows remote code execution. Only applications using
@payloadcms/plugin-import-exportare affected; fixed in 3.88.0. Workaround: disable the plugin or restrict its endpoints. - Field access control bypass on auth collections (GHSA-vc4h-q48j-5hcx, CVE-2026-105851). The duplicate operation copied field values even when a field was hidden or its read or create access rule would reject the caller, and the
disableDuplicatesetting on auth collections did not stop it. Fixed in 3.90.0 and 4.0.0-canary.34.
The rest of the batch covers, among others, an API key disclosure through ordinary document reads, a ReDoS in multipart Content-Type validation, access control in the Stripe and MCP plugins, and password hashes using too few PBKDF2 iterations.
What to do. Because the fixes land in two versions, the safe target is 3.90.0 or later on the 3.x line.
Primary source
GitHub Advisory Database
https://github.com/advisories/GHSA-v49j-62m6-pgrrWritten by Serguey Asael Shinder / Serguey Shinder.