Appsecure logo

CVE-2026-25544: Critical Vulnerability in payloadcms payload

CVE-2026-25544 is a critical SQL injection vulnerability in the payloadcms payload component. It allows unauthenticated attackers to access sensitive data, posing a significant risk to organizations. Immediate patching is necessary.

CRITICALCVSS 9.8 · Published February 6, 2026

Not a customer? See how AppSecure simulates real world attacks to protect your infrastructure.

Speak to Experts

CVE-2026-25544 represents a critical vulnerability in the payload component of payloadcms, a free and open-source headless content management system. This vulnerability allows for blind SQL injection attacks due to improper handling of user input when querying JSON or richText fields. The issue exists in versions prior to 3.73.0, where user input was directly embedded into SQL statements without escaping. An attacker can exploit this vulnerability without authentication, extracting sensitive data such as emails and password reset tokens, potentially leading to complete account takeover without the need for password cracking.

The CVSS score for this vulnerability is 9.8, categorizing it as critical. This high severity indicates a significant risk to organizations that utilize the affected versions of payloadcms. Given the potential for unauthorized data access and account takeover, organizations must prioritize remediation efforts.

The vulnerability was published on February 6, 2026, and has since been analyzed, with a fix implemented in version 3.73.0. The urgency for patching is emphasized by the vulnerability's exploitability, which remains critical due to the lack of public exploits or known active exploitation.

Organizations using versions of payloadcms prior to 3.73.0 should take immediate action to update their systems to mitigate the risks associated with this vulnerability.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Latest CVEs. Recently published vulnerabilities from the NVD database.

View all vulnerabilities
CVE IDSeverity
CVE-2025-65418HIGH
CVE-2025-65417MEDIUM
CVE-2025-65416MEDIUM
CVE-2025-65415MEDIUM
CVE-2025-61314HIGH

Protect Your Business with Hacker-Focused Approach.