VendorsPayload CMSpayloadany version
Vulnerabilities

Payload CMS Payload any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2026-25544
Payload has an SQL Injection in JSON/RichText Queries on PostgreSQL/SQLite Adapters
Published 2026-02-06 · Analyzed
9.81 PoCEPSS 0.009
CVE-2026-34751
Payload has Unvalidated Input in Password Recovery Endpoints
Published 2026-04-01 · Analyzed
9.1EPSS 0.004
CVE-2026-34748
@payloadcms/next has Stored XSS in Admin Panel
Published 2026-04-01 · Analyzed
8.7EPSS 0.004
CVE-2026-34747
Payload has an SQL Injection via Query Handling
Published 2026-04-01 · Analyzed
8.5EPSS 0.004
CVE-2026-34746
Payload has Authenticated SSRF via Upload Functionality
Published 2026-04-01 · Analyzed
7.7EPSS 0.004
CVE-2023-30843
Payload's hidden fields can be leaked on readable collections
Published 2023-04-26 · Modified
7.4EPSS 0.006
CVE-2026-27567
Payload has Server-Side Request Forgery (SSRF) in External File URL Uploads
Published 2026-02-24 · Analyzed
6.5EPSS 0.004
CVE-2026-34750
Payload has Insufficient Filename Validation in Client-Upload Signed-URL Endpoints
Published 2026-04-01 · Analyzed
6.5EPSS 0.004
CVE-2026-25574
Payload Affected by Cross-Collection IDOR in payload-preferences Access Control (Multi-Auth Environments)
Published 2026-02-06 · Analyzed
5.4EPSS 0.002
CVE-2026-34749
Payload has a CSRF Protection Bypass in Authentication Flow
Published 2026-04-01 · Analyzed
5.4EPSS 0.002