CVE-2026-105862 - Payload: Bypassed sanitization of user uploaded SVGs
CVE ID :CVE-2026-105862 Published : Oct. 6, 2026, 4:37 p.m. | 50 minutes ago Description :Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, a collection that allows downloadable SVG uploads can store a...