payload
npm29 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting payloadpage 1 of 1
- CVE-2022-27952CRITICALCVSS 9.8EG 9.8fixed in 0.15.12022-04-12
An arbitrary file upload vulnerability in the file upload module of PayloadCMS v0.15.0 allows attackers to execute arbitrary code via a crafted SVG file.
- CVE-2023-30843HIGHCVSS 7.4EG 7.4fixed in 1.7.02023-04-26
Payload is a free and open source headless content management system. In versions prior to 1.7.0, if a user has access to documents that contain hidden fields or fields they do not have access to, the user could reverse-engineer those valu…
- CVE-2025-4643MEDIUMCVSS 6.3EG 6.3fixed in 3.44.02025-08-29
Payload uses JSON Web Tokens (JWT) for authentication. After log out JWT is not invalidated, which allows an attacker who has stolen or intercepted token to freely reuse it until expiration date (which is by default set to 2 hours, but can…
- CVE-2025-4644MEDIUMCVSS 5.3EG 5.3fixed in 3.44.02025-08-29
A Session Fixation vulnerability existed in Payload's SQLite adapter due to identifier reuse during account creation. A malicious attacker could create a new account, save its JSON Web Token (JWT), and then delete the account, which did no…
- CVE-2026-105804MEDIUMCVSS 5.7EG 5.7fixed in 3.90.0 or 4.0.0-canary.34, by version range2026-10-06
Payload is a free and open source headless content management system. Payload versions from 3.0.0 before 3.90.0 and canary versions from 4.0.0-canary.0 before 4.0.0-canary.34 use a lower-than-recommended PBKDF2 work factor for password has…
- CVE-2026-105805MEDIUMCVSS 6.9EG 6.9fixed in 3.88.0 or 4.0.0-canary.27, by version range2026-10-06
Payload is a free and open source headless content management system. In versions before 3.88.0 and canary versions before 4.0.0-canary.27, an untrusted user who can query a readable collection, control its sorting, and select a protected …
- CVE-2026-105845CRITICALCVSS 9.8EG 9.8fixed in 3.88.0 or 4.0.0-canary.27, by version range2026-10-06
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an untrusted user who can query readable collections through dynamic filters or joins ca…
- CVE-2026-105846MEDIUMCVSS 6.1EG 6.1fixed in 3.88.0 or 4.0.0-canary.27, by version range2026-10-06
Payload is a free and open source headless content management system. In versions from 3.40.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an attacker can craft a redirect URL parameter that sends a guest user to an untrusted …
- CVE-2026-105847HIGHCVSS 7.1EG 7.1fixed in 3.90.0 or 4.0.0-canary.34, by version range2026-10-06
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, a user who can query a collection with a polymorphic join to sensitive fields can infer …
- CVE-2026-105849HIGHCVSS 7.7EG 7.7fixed in 3.90.0 or 4.0.0-canary.34, by version range2026-10-06
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, users with ordinary read access to other authentication documents in a collection with u…
- CVE-2026-105852MEDIUMCVSS 6.9EG 6.9fixed in 3.90.0 or 4.0.0-canary.34, by version range2026-10-06
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, querying a readable collection with a relationship to another collection can expose information abo…
- CVE-2026-105853HIGHCVSS 7.1EG 7.1fixed in 3.90.0 or 4.0.0-canary.34, by version range2026-10-06
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, token refresh responses and password reset responses can independently return hidden or …
- CVE-2026-105854HIGHCVSS 8.7EG 8.7fixed in 3.90.0 or 4.0.0-canary.34, by version range2026-10-06
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, a malformed multipart request body can cause multipart Content-Type processing to take a…
- CVE-2026-105855HIGHCVSS 7.6EG 7.6fixed in 3.90.0 or 4.0.0-canary.34, by version range2026-10-06
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, the server fails to enforce a field-level access.update restriction on the password field of an aut…
- CVE-2026-105858HIGHCVSS 8.1EG 8.1fixed in 3.90.0 or 4.0.0-canary.34, by version range2026-10-06
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, a crafted request to the public first-register operation can execute code remotely when local authe…
- CVE-2026-105859CRITICALCVSS 9.8EG 9.8fixed in 3.90.0 or 4.0.0-canary.34, by version range2026-10-06
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can submit a request to a specific update endpoint that modifies collection documents w…
- CVE-2026-105861HIGHCVSS 7.2EG 7.2fixed in 3.90.0 or 4.0.0-canary.34, by version range2026-10-06
Payload is a free and open source headless content management system. In versions after 3.0.0 and before 3.90.0, authenticated external URL-based upload retrieval can forward authentication data to a redirected destination that was not ver…
- CVE-2026-105862HIGHCVSS 8.7EG 8.7fixed in 3.90.0 or 4.0.0-canary.34, by version range2026-10-06
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, a collection that allows downloadable SVG uploads can store a malicious SVG that bypasses sanitizat…
- CVE-2026-105863CRITICALCVSS 9.2EG 9.2fixed in 3.90.0 or 4.0.0-canary.34, by version range2026-10-06
Payload is a free and open source headless content management system. In versions after 3.0.0 and before 3.90.0, a custom field option that maps a field to a reserved authentication claim name can place unintended values in the authenticat…
- CVE-2026-105865HIGHCVSS 8.1EG 8.1fixed in 3.90.0 or 4.0.0-canary.34, by version range2026-10-06
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user who can update or delete uploads stored locally can cause file cleanup to rem…
- CVE-2026-105866MEDIUMCVSS 6.9EG 6.9fixed in 3.90.0 or 4.0.0-canary.34, by version range2026-10-06
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an unauthenticated attacker who knows an account email address or username can abuse the account lo…
- CVE-2026-105868HIGHCVSS 8.6EG 8.6fixed in 3.90.0 or 4.0.0-canary.34, by version range2026-10-06
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, local upload configurations that accept XML files can store an XML file and stylesheet that execute…
- CVE-2026-11779MEDIUMCVSS 5.3EG 5.32026-06-26
An Improper Authorization vulnerability exists in PayloadCMS version 3.84.1 due to insufficient access control on the account unlock operation.
- CVE-2026-25574MEDIUMCVSS 5.4EG 5.4fixed in 3.74.02026-02-06
Payload is a free and open source headless content management system. Prior to 3.74.0, a cross-collection Insecure Direct Object Reference (IDOR) vulnerability exists in the payload-preferences internal collection. In multi-auth collection…
- CVE-2026-27567MEDIUMCVSS 4.8EG 4.8fixed in 3.75.02026-02-24
Payload is a free and open source headless content management system. Prior to 3.75.0, a Server-Side Request Forgery (SSRF) vulnerability exists in Payload's external file upload functionality. When processing external URLs for file upload…
- CVE-2026-34746HIGHCVSS 7.7EG 7.7fixed in 3.79.12026-04-01
Payload is a free and open source headless content management system. Prior to version 3.79.1, an authenticated Server-Side Request Forgery (SSRF) vulnerability exists in the upload functionality. Authenticated users with create or update …
- CVE-2026-34747HIGHCVSS 8.5EG 8.5fixed in 3.79.12026-04-01
Payload is a free and open source headless content management system. Prior to version 3.79.1, certain request inputs were not properly validated. An attacker could craft requests that influence SQL query execution, potentially exposing or…
- CVE-2026-34749MEDIUMCVSS 5.4EG 5.4fixed in 3.79.12026-04-01
Payload is a free and open source headless content management system. Prior to version 3.79.1, a Cross-Site Request Forgery (CSRF) vulnerability exists in the authentication flow. Under certain conditions, the configured CSRF protection co…
- CVE-2026-34751CRITICALCVSS 9.1EG 9.1fixed in 3.79.12026-04-01
Payload is a free and open source headless content management system. Prior to version 3.79.1 in @payloadcms/graphql and payload, a vulnerability in the password recovery flow could allow an unauthenticated attacker to perform actions on b…
Check whether payload is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for payload CVEs against the assets you own.
Book a Demo →