Payloadcms

Payload

43 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.31%
  • Veröffentlicht 06.10.2026 16:09:49
  • Zuletzt bearbeitet 06.10.2026 20:03:40

Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, users with ordinary read access to other authentication documents in a collection with useAPIKey en...

  • EPSS 0.25%
  • Veröffentlicht 06.10.2026 16:07:53
  • Zuletzt bearbeitet 09.10.2026 02:16:55

Payload is a free and open source headless content management system. In @payloadcms/plugin-stripe versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user who can reach the enabled optional Stripe REST proxy can perfo...

  • EPSS 0.25%
  • Veröffentlicht 06.10.2026 16:02:55
  • Zuletzt bearbeitet 06.10.2026 20:03:40

Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, a user who can query a collection with a polymorphic join to sensitive fields can infer hidden or r...

  • EPSS 0.23%
  • Veröffentlicht 06.10.2026 16:01:30
  • Zuletzt bearbeitet 06.10.2026 20:03:40

Payload is a free and open source headless content management system. In versions from 3.40.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an attacker can craft a redirect URL parameter that sends a guest user to an untrusted destination...

  • EPSS 0.38%
  • Veröffentlicht 06.10.2026 15:58:51
  • Zuletzt bearbeitet 06.10.2026 20:03:40

Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an untrusted user who can query readable collections through dynamic filters or joins can submit a ...

  • EPSS 0.52%
  • Veröffentlicht 06.10.2026 15:57:05
  • Zuletzt bearbeitet 09.10.2026 02:16:55

Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an unauthenticated user can submit prototype-sensitive field paths when @payloadcms/plugin-import-e...

  • EPSS 0.25%
  • Veröffentlicht 06.10.2026 15:35:17
  • Zuletzt bearbeitet 06.10.2026 20:03:40

Payload is a free and open source headless content management system. In @payloadcms/plugin-mcp versions from 3.61.0 until 3.88.0, an authenticated user can manage MCP API keys outside the intended account, enabling privilege escalation through accou...

  • EPSS 0.28%
  • Veröffentlicht 06.10.2026 15:25:29
  • Zuletzt bearbeitet 06.10.2026 20:03:40

Payload is a free and open source headless content management system. In versions before 3.88.0 and canary versions before 4.0.0-canary.27, an untrusted user who can query a readable collection, control its sorting, and select a protected field as th...

  • EPSS 0.08%
  • Veröffentlicht 06.10.2026 15:23:14
  • Zuletzt bearbeitet 06.10.2026 20:03:40

Payload is a free and open source headless content management system. Payload versions from 3.0.0 before 3.90.0 and canary versions from 4.0.0-canary.0 before 4.0.0-canary.34 use a lower-than-recommended PBKDF2 work factor for password hashing, reduc...

  • EPSS 0.18%
  • Veröffentlicht 25.09.2026 16:53:12
  • Zuletzt bearbeitet 30.09.2026 17:31:44

The @payloadcms/storage-vercel-blob storage adapter for Payload contains an improper access control vulnerability that allows authenticated users to bypass collection-level permissions by accessing the client-upload route directly. Attackers can uplo...