Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
6554 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (7.1) | — | — | Payloadcms DB MongodbAI | 6/10/2026 | 6/10/2026 | Payload is a free and open source headless content management system. In @payloadcms/db-mongodb versions before 3.87.0 and canary versions before 4.0.0-canary.20, an authenticated user who can update a document can modify fields that field-level write access control does not permit that user to change. The Postgres… | |
| Recibida | Alta (8.6) | — | — | Payloadcms PayloadAI | 6/10/2026 | 6/10/2026 | Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, local upload configurations that accept XML files can store an XML file and stylesheet that execute JavaScript in the Payload origin when a logged-in user opens the file. This… | |
| Recibida | Alta (7.1) | — | — | Payloadcms Storage S3AI | 6/10/2026 | 6/10/2026 | Payload is a free and open source headless content management system. In @payloadcms/storage-s3 versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user can overwrite an existing S3 object belonging to another upload collection when client uploads are enabled for multiple collections… | |
| Recibida | Media (6.9) | — | — | Payloadcms PayloadAI | 6/10/2026 | 6/10/2026 | Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an unauthenticated attacker who knows an account email address or username can abuse the account lockout mechanism of a local-authentication collection to prevent that account… | |
| Recibida | Alta (8.1) | — | — | Payloadcms PayloadAI | 6/10/2026 | 6/10/2026 | Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user who can update or delete uploads stored locally can cause file cleanup to remove unintended files outside the configured upload directory, resulting in data… | |
| Recibida | Media (5.3) | — | — | Payloadcms Plugin Multi TenantAI | 6/10/2026 | 6/10/2026 | Payload is a free and open source headless content management system. In @payloadcms/plugin-multi-tenant versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user limited to one tenant can create a record in another tenant when at least one tenant-enabled collection exists. Reads and… | |
| Recibida | Crítica (9.2) | — | — | Payloadcms PayloadAI | 6/10/2026 | 6/10/2026 | Payload is a free and open source headless content management system. In versions after 3.0.0 and before 3.90.0, a custom field option that maps a field to a reserved authentication claim name can place unintended values in the authentication token issued at login. This issue is fixed in version 3.90.0. | |
| Recibida | Alta (8.7) | — | — | Payloadcms PayloadAI | 6/10/2026 | 6/10/2026 | Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, a collection that allows downloadable SVG uploads can store a malicious SVG that bypasses sanitization and executes attacker-controlled JavaScript when a user downloads and opens… | |
| Recibida | Alta (7.2) | — | — | Payloadcms PayloadAI | 6/10/2026 | 6/10/2026 | Payload is a free and open source headless content management system. In versions after 3.0.0 and before 3.90.0, authenticated external URL-based upload retrieval can forward authentication data to a redirected destination that was not verified as trusted, potentially exposing a valid session to an unintended… | |
| Recibida | Alta (7.1) | — | — | Payloadcms Plugin Multi TenantAI | 6/10/2026 | 6/10/2026 | Payload is a free and open source headless content management system. In @payloadcms/plugin-multi-tenant versions before 3.90.0 and canary versions before 4.0.0-canary.34, the default tenant array field access allows an authenticated user to assign the user's own account to other tenants. Deployments that replace the… | |
| Recibida | Crítica (9.8) | — | — | Payloadcms PayloadAI | 6/10/2026 | 6/10/2026 | Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can submit a request to a specific update endpoint that modifies collection documents without enforcing collection or field-level access control when orderable is… | |
| Recibida | Alta (8.1) | — | — | Payloadcms PayloadAI | 6/10/2026 | 6/10/2026 | Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, a crafted request to the public first-register operation can execute code remotely when local authentication is enabled and no initial user has been created. This issue is fixed… | |
| Recibida | Crítica (10) | — | — | Payloadcms Plugin Form BuilderAI | 6/10/2026 | 6/10/2026 | Payload is a free and open source headless content management system. In @payloadcms/plugin-form-builder versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can craft a form submission that executes code remotely on the server. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34. | |
| Recibida | Alta (8.6) | — | — | Payloadcms PayloadAI | 6/10/2026 | 6/10/2026 | Payload is a free and open source headless content management system. Prior to 3.90.0 and 4.0.0-canary.34, an attacker with read and create or update access to a collection containing a json field or a blocks field with blocksAsJSON enabled can inject SQL through a crafted field path and operators. Collections without… | |
| Recibida | Alta (7.6) | — | — | Payloadcms PayloadAI | 6/10/2026 | 6/10/2026 | Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, the server fails to enforce a field-level access.update restriction on the password field of an authentication collection. This issue is fixed in versions 3.90.0 and… | |
| Recibida | Alta (8.7) | — | — | Payloadcms PayloadAI | 6/10/2026 | 6/10/2026 | Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, a malformed multipart request body can cause multipart Content-Type processing to take an extremely long time, resulting in uncontrolled resource consumption. This… | |
| Recibida | Alta (7.1) | — | — | Payloadcms PayloadAI | 6/10/2026 | 6/10/2026 | Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, token refresh responses and password reset responses can independently return hidden or read-restricted fields that the requesting user cannot access. This issue is… | |
| Recibida | Media (6.9) | — | — | Payloadcms PayloadAI | 6/10/2026 | 6/10/2026 | Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, querying a readable collection with a relationship to another collection can expose information about related documents protected by access.read where constraints. This issue is… | |
| Recibida | Crítica (9.3) | — | — | Payloadcms PayloadAI | 6/10/2026 | 6/10/2026 | Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, the duplicate operation copies values from a source document even when a field is hidden or its access.read or access.create rule rejects that value for the caller. The… | |
| Recibida | Alta (8.8) | — | — | Payloadcms Plugin EcommerceAI | 6/10/2026 | 6/10/2026 | Payload is a free and open source headless content management system. In @payloadcms/plugin-ecommerce versions before 3.90.0 and canary versions before 4.0.0-canary.34, use of the Stripe payment adapter can allow a Stripe order confirmation to be processed more than once under certain conditions. This issue is fixed… | |
| Recibida | Alta (7.7) | — | — | Payloadcms PayloadAI | 6/10/2026 | 6/10/2026 | Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, users with ordinary read access to other authentication documents in a collection with useAPIKey enabled can obtain active API keys and exercise the target accounts'… | |
| Recibida | Media (6.4) | — | — | Payloadcms Plugin StripeAI | 6/10/2026 | 6/10/2026 | Payload is a free and open source headless content management system. In @payloadcms/plugin-stripe versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user who can reach the enabled optional Stripe REST proxy can perform unintended Stripe operations. This issue is fixed in versions… | |
| Recibida | Alta (7.1) | — | — | Payloadcms PayloadAI | 6/10/2026 | 6/10/2026 | Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, a user who can query a collection with a polymorphic join to sensitive fields can infer hidden or read-restricted values, including password-reset tokens, through… | |
| Recibida | Media (6.1) | — | — | Payloadcms PayloadAI | 6/10/2026 | 6/10/2026 | Payload is a free and open source headless content management system. In versions from 3.40.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an attacker can craft a redirect URL parameter that sends a guest user to an untrusted destination after the authentication flow completes. This issue is fixed in… | |
| Recibida | Crítica (9.8) | — | — | Payloadcms PayloadAI | 6/10/2026 | 6/10/2026 | Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an untrusted user who can query readable collections through dynamic filters or joins can submit a request that causes SQL injection in the SQLite and Postgres… |