CVE Browser
Payload: Field-level write access bypass in Payload on MongoDB
Payload: Uploaded XML files could execute same-origin JavaScript
Payload: Client uploads could overwrite S3 objects
Payload: Unauthenticated account-lockout denial of service
Payload: Incomplete validation during the upload file lifecycle
Payload: Cross-tenant create in @payloadcms/plugin-multi-tenant
Payload authentication token field handling issue
Payload: Bypassed sanitization of user uploaded SVGs
Payload external upload trust validation issue
Payload: Tenant authorization bypass in Multi-Tenant Plugin
Payload: Unauthorized update to collection documents
Payload: Remote Code Execution through first-register
Payload: RCE in Payload Form Builder
Payload: SQL injection in SQLite/Postgres
Payload: Field-level password update restrictions were not enforced
Payload: ReDoS in Multipart Content-Type Validation
Payload: Token refresh and password reset responses may expose restricted user fields
Payload relationship-query authorization bypass
Payload: Field access control bypass on auth collections
Payload: Order confirmation validation issue in Payload Ecommerce
Payload: API key disclosure through ordinary document reads
Payload: Insufficient Access Control in Stripe REST Proxy
Payload: Polymorphic join queries could disclose hidden fields
Payload: Untrusted redirect URL parameter exploit
Payload: SQL Injection in SQLite and Postgres
Showing 1 to 25 CVEs · page 1 (more available)