{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3apayloadcmspayload_cms/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:payloadcms:payload_cms:*:*:*:*:*:*:*:*","cpe:2.3:a:payloadcms:payload:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-25544"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Payload CMS (\u003c 3.73.0)"],"_cs_severities":["high"],"_cs_tags":["webapps","sqli","vulnerability"],"_cs_type":"threat","_cs_vendors":["Payload CMS"],"content_html":"\u003cp\u003ePayload CMS versions prior to 3.73.0 contain a critical Blind SQL Injection vulnerability, identified as CVE-2026-25544. The vulnerability occurs during the processing of 'where' filters in API requests, specifically when the application interacts with JSON or RichText fields utilizing the Drizzle database adapter. An attacker can supply a crafted JSON payload within the 'where' filter parameter to manipulate generated JSONPath expressions, potentially allowing for unauthorized data exfiltration or database state inference. Given that a functional proof-of-concept exploit is publicly available, organizations running impacted versions are at an elevated risk of exploitation.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies an internet-facing endpoint running Payload CMS, such as /api/posts.\u003c/li\u003e\n\u003cli\u003eAttacker probes the 'where' query parameter to determine if it accepts complex JSON structures.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious JSON payload containing SQL injection characters (e.g., '|| @ == @ || @ == ') to target specific database fields.\u003c/li\u003e\n\u003cli\u003eThe application receives the request and passes the attacker-supplied 'where' filter to the Drizzle database adapter.\u003c/li\u003e\n\u003cli\u003eThe Drizzle adapter fails to sanitize the input, incorporating the malicious SQL syntax into the query executed against the backend PostgreSQL database.\u003c/li\u003e\n\u003cli\u003eThe backend database processes the injected query and returns a modified result set, indicating successful blind SQL injection through time-based or boolean-based inference.\u003c/li\u003e\n\u003cli\u003eAttacker iteratively exfiltrates data from the database by observing the application's responses to varying injected conditions.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to infer sensitive information from the underlying PostgreSQL database. This can lead to unauthorized data disclosure, including user credentials, metadata, or other proprietary application data stored within the CMS.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the following actions to mitigate this threat:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of Payload CMS to version 3.73.0 or later to patch CVE-2026-25544.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation on the API gateway level to block requests containing anomalous characters or SQL operators within 'where' filter parameters if an immediate upgrade is not feasible.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious requests to API endpoints that contain high concentrations of special characters in the 'where' query parameter.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-01T14:31:32Z","date_published":"2026-09-01T14:31:32Z","id":"https://feed.craftedsignal.io/briefs/2026-09-payload-cms-sqli/","summary":"Payload CMS versions prior to 3.73.0 are vulnerable to Blind SQL Injection via maliciously crafted JSON filter inputs processed by the Drizzle database adapter.","title":"Blind SQL Injection Vulnerability in Payload CMS","url":"https://feed.craftedsignal.io/briefs/2026-09-payload-cms-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:payloadcms:payload_cms:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}