CVE Browser

More filters (active)

Page 1 (more results available)

Vendor: Payloadcms Remove filter Clear all
CVE-2026-106100 HIGH

Payload: Field-level write access bypass in Payload on MongoDB

CVSS 7.1 EPSS n/a Oct 6, 2026
CVE-2026-105868 HIGH

Payload: Uploaded XML files could execute same-origin JavaScript

CVSS 8.6 EPSS n/a Oct 6, 2026
CVE-2026-105867 HIGH

Payload: Client uploads could overwrite S3 objects

CVSS 7.1 EPSS n/a Oct 6, 2026
CVE-2026-105866 MEDIUM

Payload: Unauthenticated account-lockout denial of service

CVSS 6.9 EPSS n/a Oct 6, 2026
CVE-2026-105865 HIGH

Payload: Incomplete validation during the upload file lifecycle

CVSS 8.1 EPSS n/a Oct 6, 2026
CVE-2026-105864 MEDIUM

Payload: Cross-tenant create in @payloadcms/plugin-multi-tenant

CVSS 5.3 EPSS n/a Oct 6, 2026
CVE-2026-105863 CRITICAL

Payload authentication token field handling issue

CVSS 9.2 EPSS n/a Oct 6, 2026
CVE-2026-105862 HIGH

Payload: Bypassed sanitization of user uploaded SVGs

CVSS 8.7 EPSS n/a Oct 6, 2026
CVE-2026-105861 HIGH

Payload external upload trust validation issue

CVSS 7.2 EPSS n/a Oct 6, 2026
CVE-2026-105860 HIGH

Payload: Tenant authorization bypass in Multi-Tenant Plugin

CVSS 7.1 EPSS n/a Oct 6, 2026
CVE-2026-105859 CRITICAL

Payload: Unauthorized update to collection documents

CVSS 9.8 EPSS n/a Oct 6, 2026
CVE-2026-105858 HIGH

Payload: Remote Code Execution through first-register

CVSS 8.1 EPSS n/a Oct 6, 2026
CVE-2026-105857 CRITICAL

Payload: RCE in Payload Form Builder

CVSS 10.0 EPSS n/a Oct 6, 2026
CVE-2026-105856 HIGH

Payload: SQL injection in SQLite/Postgres

CVSS 8.6 EPSS n/a Oct 6, 2026
CVE-2026-105855 HIGH

Payload: Field-level password update restrictions were not enforced

CVSS 7.6 EPSS n/a Oct 6, 2026
npm
CVE-2026-105854 HIGH

Payload: ReDoS in Multipart Content-Type Validation

CVSS 8.7 EPSS n/a Oct 6, 2026
npm
CVE-2026-105853 HIGH

Payload: Token refresh and password reset responses may expose restricted user fields

CVSS 7.1 EPSS n/a Oct 6, 2026
npm
CVE-2026-105852 MEDIUM

Payload relationship-query authorization bypass

CVSS 6.9 EPSS n/a Oct 6, 2026
npm
CVE-2026-105851 CRITICAL

Payload: Field access control bypass on auth collections

CVSS 9.3 EPSS n/a Oct 6, 2026
CVE-2026-105850 HIGH

Payload: Order confirmation validation issue in Payload Ecommerce

CVSS 8.8 EPSS n/a Oct 6, 2026
npm
CVE-2026-105849 HIGH

Payload: API key disclosure through ordinary document reads

CVSS 7.7 EPSS n/a Oct 6, 2026
npm
CVE-2026-105848 MEDIUM

Payload: Insufficient Access Control in Stripe REST Proxy

CVSS 6.4 EPSS n/a Oct 6, 2026
npm
CVE-2026-105847 HIGH

Payload: Polymorphic join queries could disclose hidden fields

CVSS 7.1 EPSS n/a Oct 6, 2026
npm
CVE-2026-105846 MEDIUM

Payload: Untrusted redirect URL parameter exploit

CVSS 6.1 EPSS n/a Oct 6, 2026
npm
CVE-2026-105845 CRITICAL

Payload: SQL Injection in SQLite and Postgres

CVSS 9.8 EPSS n/a Oct 6, 2026
npm

Showing 1 to 25 CVEs · page 1 (more available)