Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Payload HIGH 8.7
CVE-2026-34748

Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/next, a stored Cross-Site Scripting (XSS…

Fix: 3.78.0+
Fix from $1,950 2026-04-01
Payload MEDIUM 6.5
CVE-2026-34750

Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/storage-azure, @payloadcms/storage-gcs, …

Fix: 3.78.0+
Fix from $1,600 2026-04-01
Payload MEDIUM 5.4
CVE-2026-34749

Payload is a free and open source headless content management system. Prior to version 3.79.1, a Cross-Site Request Forgery (CSRF) vulnerability exis…

Fix: 3.79.1+
Fix from $1,600 2026-04-01
Payload HIGH 8.2
CVE-2026-34747

Payload is a free and open source headless content management system. Prior to version 3.79.1, certain request inputs were not properly validated. An…

Fix: 3.79.1+
Fix from $1,950 2026-04-01
Payload HIGH 7.7
CVE-2026-34746

Payload is a free and open source headless content management system. Prior to version 3.79.1, an authenticated Server-Side Request Forgery (SSRF) vu…

Fix: 3.79.1+
Fix from $1,950 2026-04-01
Payload CRITICAL 9.1
CVE-2026-34751

Payload is a free and open source headless content management system. Prior to version 3.79.1 in @payloadcms/graphql and payload, a vulnerability in …

Fix: 3.79.1+
Fix from $2,300 2026-04-01
Payload CRITICAL 9.8
CVE-2026-25544

Payload is a free and open source headless content management system. Prior to 3.73.0, when querying JSON or richText fields, user input was directly…

Fix: 3.73.0+
Fix from $2,300 2026-02-06
Payload MEDIUM 5.4
CVE-2026-25574

Payload is a free and open source headless content management system. Prior to 3.74.0, a cross-collection Insecure Direct Object Reference (IDOR) vul…

Fix: 3.74.0+
Fix from $1,600 2026-02-06
Payload MEDIUM 6.5
CVE-2023-30843

Payload is a free and open source headless content management system. In versions prior to 1.7.0, if a user has access to documents that contain hidd…

Fix: 1.7.0+
Fix from $1,600 2023-04-26
Payload CRITICAL 9.8
CVE-2022-27952

An arbitrary file upload vulnerability in the file upload module of PayloadCMS v0.15.0 allows attackers to execute arbitrary code via a crafted SVG f…

No fix yet
Fix from $2,300 2022-04-12