« Volver al listado

Payloadcms

Payloadcms Payload: vulnerabilidades y CVE

Payloadcms Payload tiene 13 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE13
Últimos 12 meses9
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-34750Media (6.5)0.41%—1 abr 2026
Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/storage-azure, @payloadcms/storage-gcs, @payloadcms/storage-r2, and @payloadcms/storage-s3, the client-upload…
CVE-2026-34749Media (5.4)0.16%—1 abr 2026
Payload is a free and open source headless content management system. Prior to version 3.79.1, a Cross-Site Request Forgery (CSRF) vulnerability exists in the authentication flow. Under certain conditions, the…
CVE-2026-34748Alta (8.7)0.36%—1 abr 2026
Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/next, a stored Cross-Site Scripting (XSS) vulnerability existed in the admin panel. An authenticated user with…
CVE-2026-34747Alta (8.2)0.40%—1 abr 2026
Payload is a free and open source headless content management system. Prior to version 3.79.1, certain request inputs were not properly validated. An attacker could craft requests that influence SQL query execution,…
CVE-2026-34746Alta (7.7)0.35%—1 abr 2026
Payload is a free and open source headless content management system. Prior to version 3.79.1, an authenticated Server-Side Request Forgery (SSRF) vulnerability exists in the upload functionality. Authenticated users…
CVE-2026-34751Crítica (9.1)0.43%—1 abr 2026
Payload is a free and open source headless content management system. Prior to version 3.79.1 in @payloadcms/graphql and payload, a vulnerability in the password recovery flow could allow an unauthenticated attacker to…
CVE-2026-27567Media (4.8)0.41%—24 feb 2026
Payload is a free and open source headless content management system. Prior to 3.75.0, a Server-Side Request Forgery (SSRF) vulnerability exists in Payload's external file upload functionality. When processing external…
CVE-2026-25574Media (5.4)0.24%—6 feb 2026
Payload is a free and open source headless content management system. Prior to 3.74.0, a cross-collection Insecure Direct Object Reference (IDOR) vulnerability exists in the payload-preferences internal collection. In…
CVE-2026-25544Crítica (9.8)0.88%—6 feb 2026
Payload is a free and open source headless content management system. Prior to 3.73.0, when querying JSON or richText fields, user input was directly embedded into SQL without escaping, enabling blind SQL injection…
CVE-2025-4644Media (5.3)0.41%—29 ago 2025
A Session Fixation vulnerability existed in Payload's SQLite adapter due to identifier reuse during account creation. A malicious attacker could create a new account, save its JSON Web Token (JWT), and then delete the…
CVE-2025-4643Media (6.3)0.40%—29 ago 2025
Payload uses JSON Web Tokens (JWT) for authentication. After log out JWT is not invalidated, which allows an attacker who has stolen or intercepted token to freely reuse it until expiration date (which is by default set…
CVE-2023-30843Media (6.5)0.63%—26 abr 2023
Payload is a free and open source headless content management system. In versions prior to 1.7.0, if a user has access to documents that contain hidden fields or fields they do not have access to, the user could…
CVE-2022-27952Crítica (9.8)2.3%—12 abr 2022
An arbitrary file upload vulnerability in the file upload module of PayloadCMS v0.15.0 allows attackers to execute arbitrary code via a crafted SVG file.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application3
  2. T1005 Data from Local System2
  3. T1059.007 JavaScript1
  4. T1078.001 Default Accounts1
  5. T1090 Proxy1
  6. T1189 Drive-by Compromise1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Payloadcms