Payloadcms

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 14
    Known Exploited: 0
    3
    Critical Level Threats
    4
    High Level Threats
    4
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-11779

    PayloadCMS 3.84.1 - Authenticated account lockout bypass through default unlock access

    Last Modified: Jun 26, 2026
    Published: Jun 26, 2026

    CVE-2026-34750

    Payload has Insufficient Filename Validation in Client-Upload Signed-URL Endpoints

    Last Modified: Apr 14, 2026
    Published: Apr 01, 2026

    CVE-2026-34749

    Payload has a CSRF Protection Bypass in Authentication Flow

    Last Modified: Apr 14, 2026
    Published: Apr 01, 2026

    CVE-2026-34748

    @payloadcms/next has Stored XSS in Admin Panel

    Last Modified: Apr 14, 2026
    Published: Apr 01, 2026

    CVE-2026-34747

    Payload has an SQL Injection via Query Handling

    Last Modified: Apr 14, 2026
    Published: Apr 01, 2026
    Items Per Page