Impact
An attacker can submit a specially crafted form via the Payload CMS form builder plugin, allowing remote execution of arbitrary code on the hosting server. The vulnerability stems from improper validation of form payloads and the use of unsafe evaluation functions (CWE‑1321 and CWE‑94). Successful exploitation compromises server confidentiality, integrity, and availability by enabling attacker‑controlled commands.
Affected Systems
Payload CMS, specifically the form builder plugin in versions earlier than 3.90.0 and canary releases before 4.0.0‑canary.34, is susceptible. Updating to v3.90.0 or v4.0.0‑canary.34 removes the flaw.
Risk and Exploitability
The CVSS score of 10 indicates critical severity, and the lack of an EPSS score shows current exploit data is unavailable; however, the vulnerability is listed in the official advisories and has a direct web‑based attack path via form submissions. An attacker who can reach the form endpoint can trigger code execution, implying high risk for exposed installations. The risk warrants urgent remediation.
OpenCVE Enrichment