Payloadcms

Payload

43 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.22%
  • Veröffentlicht 06.10.2026 16:56:55
  • Zuletzt bearbeitet 06.10.2026 20:03:40

Payload is a free and open source headless content management system. In @payloadcms/db-mongodb versions before 3.87.0 and canary versions before 4.0.0-canary.20, an authenticated user who can update a document can modify fields that field-level writ...

  • EPSS 0.26%
  • Veröffentlicht 06.10.2026 16:51:34
  • Zuletzt bearbeitet 09.10.2026 02:16:56

Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, local upload configurations that accept XML files can store an XML file and stylesheet that execute JavaScript...

  • EPSS 0.25%
  • Veröffentlicht 06.10.2026 16:49:12
  • Zuletzt bearbeitet 06.10.2026 20:03:40

Payload is a free and open source headless content management system. In @payloadcms/storage-s3 versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user can overwrite an existing S3 object belonging to another upload c...

  • EPSS 0.35%
  • Veröffentlicht 06.10.2026 16:46:31
  • Zuletzt bearbeitet 06.10.2026 20:03:40

Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an unauthenticated attacker who knows an account email address or username can abuse the account lockout mecha...

  • EPSS 0.37%
  • Veröffentlicht 06.10.2026 16:45:09
  • Zuletzt bearbeitet 06.10.2026 20:03:40

Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user who can update or delete uploads stored locally can cause file cleanup to remove uninten...

  • EPSS 0.25%
  • Veröffentlicht 06.10.2026 16:42:27
  • Zuletzt bearbeitet 06.10.2026 20:03:40

Payload is a free and open source headless content management system. In @payloadcms/plugin-multi-tenant versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user limited to one tenant can create a record in another ten...

  • EPSS 0.39%
  • Veröffentlicht 06.10.2026 16:39:44
  • Zuletzt bearbeitet 09.10.2026 02:16:56

Payload is a free and open source headless content management system. In versions after 3.0.0 and before 3.90.0, a custom field option that maps a field to a reserved authentication claim name can place unintended values in the authentication token i...

  • EPSS 0.25%
  • Veröffentlicht 06.10.2026 16:37:59
  • Zuletzt bearbeitet 06.10.2026 20:03:40

Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, a collection that allows downloadable SVG uploads can store a malicious SVG that bypasses sanitization and exe...

  • EPSS 0.19%
  • Veröffentlicht 06.10.2026 16:34:41
  • Zuletzt bearbeitet 06.10.2026 20:03:40

Payload is a free and open source headless content management system. In versions after 3.0.0 and before 3.90.0, authenticated external URL-based upload retrieval can forward authentication data to a redirected destination that was not verified as tr...

  • EPSS 0.24%
  • Veröffentlicht 06.10.2026 16:33:20
  • Zuletzt bearbeitet 06.10.2026 20:03:40

Payload is a free and open source headless content management system. In @payloadcms/plugin-multi-tenant versions before 3.90.0 and canary versions before 4.0.0-canary.34, the default tenant array field access allows an authenticated user to assign t...