Description
Certain request inputs were not properly validated. An attacker could craft requests that influence SQL query execution, potentially exposing or modifying data in collections.
Recommendation
Update the payload package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.79.1
- Patched version(s): 3.79.1
References
Could your website be exposed too?
SmartScanner can check your website for Payload has an SQL Injection via Query Handling and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Drizzle ORM has SQL injection via improperly escaped SQL identifiers - CVE-2026-39356
- @nocobase/database has SQL Injection via String Concatenation through Recursive Eager Loading - CVE-2026-41640
- Kysely has a MySQL SQL Injection via Insufficient Backslash Escaping in `sql.lit(string)` usage or similar methods that - CVE-2026-33468
- OneUptime ClickHouse SQL Injection via Aggregate Query Parameters - CVE-2026-32306
You might also like:
See something that needs correcting? Let us knowUpdated April 06, 2026


