CVE-2026-25544

CRITICAL

Payloadcms Drizzle < 3.73.0 - SQL Injection

Title source: rule
STIX 2.1

Description

Payload is a free and open source headless content management system. Prior to 3.73.0, when querying JSON or richText fields, user input was directly embedded into SQL without escaping, enabling blind SQL injection attacks. An unauthenticated attacker could extract sensitive data (emails, password reset tokens) and achieve full account takeover without password cracking. This vulnerability is fixed in 3.73.0.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0045
EPSS Percentile 35.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-89
Status published
Products (2)
payloadcms/drizzle 0 - 3.73.0npm
payloadcms/payload < 3.73.0
Published Feb 06, 2026
Tracked Since Feb 18, 2026