Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.7 CVE-2026-34748 Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/next, a stored Cross-Site Scripting (XSS… Payload 3.78.0+ Fix from $1,9502026-04-01 MEDIUM 6.5 CVE-2026-34750 Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/storage-azure, @payloadcms/storage-gcs, … Payload 3.78.0+ Fix from $1,6002026-04-01 MEDIUM 5.4 CVE-2026-34749 Payload is a free and open source headless content management system. Prior to version 3.79.1, a Cross-Site Request Forgery (CSRF) vulnerability exis… Payload 3.79.1+ Fix from $1,6002026-04-01 HIGH 8.2 CVE-2026-34747 Payload is a free and open source headless content management system. Prior to version 3.79.1, certain request inputs were not properly validated. An… Payload 3.79.1+ Fix from $1,9502026-04-01 HIGH 7.7 CVE-2026-34746 Payload is a free and open source headless content management system. Prior to version 3.79.1, an authenticated Server-Side Request Forgery (SSRF) vu… Payload 3.79.1+ Fix from $1,9502026-04-01 CRITICAL 9.1 CVE-2026-34751 Payload is a free and open source headless content management system. Prior to version 3.79.1 in @payloadcms/graphql and payload, a vulnerability in … Payload 3.79.1+ Fix from $2,3002026-04-01 CRITICAL 9.8 CVE-2026-25544 Payload is a free and open source headless content management system. Prior to 3.73.0, when querying JSON or richText fields, user input was directly… Payload 3.73.0+ Fix from $2,3002026-02-06 MEDIUM 5.4 CVE-2026-25574 Payload is a free and open source headless content management system. Prior to 3.74.0, a cross-collection Insecure Direct Object Reference (IDOR) vul… Payload 3.74.0+ Fix from $1,6002026-02-06 MEDIUM 6.5 CVE-2023-30843 Payload is a free and open source headless content management system. In versions prior to 1.7.0, if a user has access to documents that contain hidd… Payload 1.7.0+ Fix from $1,6002023-04-26 CRITICAL 9.8 CVE-2022-27952 An arbitrary file upload vulnerability in the file upload module of PayloadCMS v0.15.0 allows attackers to execute arbitrary code via a crafted SVG f… Payload No fix yet Fix from $2,3002022-04-12