CVE-2026-27567
- EPSS 0.03%
- Veröffentlicht 24.02.2026 14:22:37
- Zuletzt bearbeitet 26.02.2026 19:59:33
Payload is a free and open source headless content management system. Prior to 3.75.0, a Server-Side Request Forgery (SSRF) vulnerability exists in Payload's external file upload functionality. When processing external URLs for file uploads, insuffic...
CVE-2026-25544
- EPSS 0.03%
- Veröffentlicht 06.02.2026 21:07:01
- Zuletzt bearbeitet 20.02.2026 20:14:42
Payload is a free and open source headless content management system. Prior to 3.73.0, when querying JSON or richText fields, user input was directly embedded into SQL without escaping, enabling blind SQL injection attacks. An unauthenticated attacke...
CVE-2026-25574
- EPSS 0.01%
- Veröffentlicht 06.02.2026 21:04:48
- Zuletzt bearbeitet 20.02.2026 20:14:13
Payload is a free and open source headless content management system. Prior to 3.74.0, a cross-collection Insecure Direct Object Reference (IDOR) vulnerability exists in the payload-preferences internal collection. In multi-auth collection environmen...
CVE-2025-4644
- EPSS 0.06%
- Veröffentlicht 29.08.2025 10:01:13
- Zuletzt bearbeitet 29.08.2025 16:24:29
A Session Fixation vulnerability existed in Payload's SQLite adapter due to identifier reuse during account creation. A malicious attacker could create a new account, save its JSON Web Token (JWT), and then delete the account, which did not invalidat...
CVE-2025-4643
- EPSS 0.07%
- Veröffentlicht 29.08.2025 10:01:09
- Zuletzt bearbeitet 29.08.2025 16:24:29
Payload uses JSON Web Tokens (JWT) for authentication. After log out JWT is not invalidated, which allows an attacker who has stolen or intercepted token to freely reuse it until expiration date (which is by default set to 2 hours, but can be changed...
CVE-2023-30843
- EPSS 0.3%
- Veröffentlicht 26.04.2023 21:15:09
- Zuletzt bearbeitet 21.11.2024 08:00:57
Payload is a free and open source headless content management system. In versions prior to 1.7.0, if a user has access to documents that contain hidden fields or fields they do not have access to, the user could reverse-engineer those values via brut...
CVE-2022-27952
- EPSS 1%
- Veröffentlicht 12.04.2022 17:15:10
- Zuletzt bearbeitet 21.11.2024 06:56:32
An arbitrary file upload vulnerability in the file upload module of PayloadCMS v0.15.0 allows attackers to execute arbitrary code via a crafted SVG file.