Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.7
CVE-2026-34748
Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/next, a stored Cross-Site Scripting (XSS…
Payload
3.78.0+
MEDIUM 6.5
CVE-2026-34750
Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/storage-azure, @payloadcms/storage-gcs, …
Payload
3.78.0+
MEDIUM 5.4
CVE-2026-34749
Payload is a free and open source headless content management system. Prior to version 3.79.1, a Cross-Site Request Forgery (CSRF) vulnerability exis…
Payload
3.79.1+
HIGH 8.2
CVE-2026-34747
Payload is a free and open source headless content management system. Prior to version 3.79.1, certain request inputs were not properly validated. An…
Payload
3.79.1+
HIGH 7.7
CVE-2026-34746
Payload is a free and open source headless content management system. Prior to version 3.79.1, an authenticated Server-Side Request Forgery (SSRF) vu…
Payload
3.79.1+
CRITICAL 9.1
CVE-2026-34751
Payload is a free and open source headless content management system. Prior to version 3.79.1 in @payloadcms/graphql and payload, a vulnerability in …
Payload
3.79.1+
CRITICAL 9.8
CVE-2026-25544
Payload is a free and open source headless content management system. Prior to 3.73.0, when querying JSON or richText fields, user input was directly…
Payload
3.73.0+
MEDIUM 5.4
CVE-2026-25574
Payload is a free and open source headless content management system. Prior to 3.74.0, a cross-collection Insecure Direct Object Reference (IDOR) vul…
Payload
3.74.0+
MEDIUM 6.5
CVE-2023-30843
Payload is a free and open source headless content management system. In versions prior to 1.7.0, if a user has access to documents that contain hidd…
Payload
1.7.0+
CRITICAL 9.8
CVE-2022-27952
An arbitrary file upload vulnerability in the file upload module of PayloadCMS v0.15.0 allows attackers to execute arbitrary code via a crafted SVG f…
Payload
No fix yet