CVE-2026-34748 identifies a stored Cross-Site Scripting (XSS) vulnerability in the admin panel of Payload CMS, specifically affecting `@payloadcms/next` versions prior to 3.78.0. An authenticated user with write access can inject malicious content that executes in another user's browser when viewed. This vulnerability has a CVSSv3.1 score of 8.7 (High), indicating a high impact on confidentiality and integrity, requiring low privileges and user interaction for exploitation. While no public exploit code is currently available and it is not known to be actively exploited, organizations using affected versions should update to 3.78.0 or later to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.78.0CPE matchmatch criteria | cpe:2.3:a:payloadcms:payload:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.