Payload

Payloadcms · 41 CVEs

CVE-2026-106100
HIGH

Payload: Field-level write access bypass in Payload on MongoDB

Oct 6, 2026

CVE-2026-105868
HIGH

Payload: Uploaded XML files could execute same-origin JavaScript

Oct 6, 2026

CVE-2026-105867
HIGH

Payload: Client uploads could overwrite S3 objects

Oct 6, 2026

CVE-2026-105866
MEDIUM

Payload: Unauthenticated account-lockout denial of service

Oct 6, 2026

CVE-2026-105865
HIGH

Payload: Incomplete validation during the upload file lifecycle

Oct 6, 2026

CVE-2026-105864
MEDIUM

Payload: Cross-tenant create in @payloadcms/plugin-multi-tenant

Oct 6, 2026

CVE-2026-105863
CRITICAL

Payload authentication token field handling issue

Oct 6, 2026

CVE-2026-105862
HIGH

Payload: Bypassed sanitization of user uploaded SVGs

Oct 6, 2026

CVE-2026-105861
HIGH

Payload external upload trust validation issue

Oct 6, 2026

CVE-2026-105860
HIGH

Payload: Tenant authorization bypass in Multi-Tenant Plugin

Oct 6, 2026

CVE-2026-105859
CRITICAL

Payload: Unauthorized update to collection documents

Oct 6, 2026

CVE-2026-105858
HIGH

Payload: Remote Code Execution through first-register

Oct 6, 2026

CVE-2026-105857
CRITICAL

Payload: RCE in Payload Form Builder

Oct 6, 2026

CVE-2026-105856
HIGH

Payload: SQL injection in SQLite/Postgres

Oct 6, 2026

CVE-2026-105855
HIGH

Payload: Field-level password update restrictions were not enforced

Oct 6, 2026

CVE-2026-105854
HIGH

Payload: ReDoS in Multipart Content-Type Validation

Oct 6, 2026

CVE-2026-105853
HIGH

Payload: Token refresh and password reset responses may expose restricted user fields

Oct 6, 2026

CVE-2026-105852
MEDIUM

Payload relationship-query authorization bypass

Oct 6, 2026

CVE-2026-105851
CRITICAL

Payload: Field access control bypass on auth collections

Oct 6, 2026

CVE-2026-105850
HIGH

Payload: Order confirmation validation issue in Payload Ecommerce

Oct 6, 2026

CVE-2026-105849
HIGH

Payload: API key disclosure through ordinary document reads

Oct 6, 2026

CVE-2026-105848
MEDIUM

Payload: Insufficient Access Control in Stripe REST Proxy

Oct 6, 2026

CVE-2026-105847
HIGH

Payload: Polymorphic join queries could disclose hidden fields

Oct 6, 2026

CVE-2026-105846
MEDIUM

Payload: Untrusted redirect URL parameter exploit

Oct 6, 2026

CVE-2026-105845
CRITICAL

Payload: SQL Injection in SQLite and Postgres

Oct 6, 2026

Showing 1 to 25 of 41 CVEs