Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Payloadcms

First CVE: Apr 12, 2022Active for: 4 yearsTotal CVEs: 13
31.1
VTI Score
Medium

Payload CMS is a headless content-management system focused on a single product line, yet occupies a prominent position among web-application platforms. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur across durable weakness classes including SQL injection, server-side request forgery, authorization bypass, cross-site request forgery, and sensitive-information exposure—patterns characteristic of web-application input handling and access-control enforcement in database-driven content platforms. Defenders should prioritize tracking this vendor's security advisories and apply patches promptly to internet-reachable instances; current severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
3.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 53% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Payloadcms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 12, 2022
4 years ago
Most Recent CVE
Apr 1, 2026
114 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-34751CRITICAL
Payload is a free and open source headless content management system. Prior to version 3.79.1 in @payloadcms/graphql and payload, a vulnerability in the password recovery flow coul
Apr 1, 20269.132NONO
CVE-2026-25544CRITICAL
Payload is a free and open source headless content management system. Prior to 3.73.0, when querying JSON or richText fields, user input was directly embedded into SQL without esca
Feb 6, 20269.832NONO
CVE-2026-34748HIGH
Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/next, a stored Cross-Site Scripting (XSS) vulnerability existed in the
Apr 1, 20268.731NONO
CVE-2026-34747HIGH
Payload is a free and open source headless content management system. Prior to version 3.79.1, certain request inputs were not properly validated. An attacker could craft requests
Apr 1, 20268.229NONO
CVE-2026-34746HIGH
Payload is a free and open source headless content management system. Prior to version 3.79.1, an authenticated Server-Side Request Forgery (SSRF) vulnerability exists in the uploa
Apr 1, 20267.727NONO
CVE-2022-27952CRITICAL
An arbitrary file upload vulnerability in the file upload module of PayloadCMS v0.15.0 allows attackers to execute arbitrary code via a crafted SVG file.
Apr 12, 20229.824NONO
CVE-2026-34750MEDIUM
Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/storage-azure, @payloadcms/storage-gcs, @payloadcms/storage-r2, and @pa
Apr 1, 20266.523NONO
CVE-2026-34749MEDIUM
Payload is a free and open source headless content management system. Prior to version 3.79.1, a Cross-Site Request Forgery (CSRF) vulnerability exists in the authentication flow.
Apr 1, 20265.421NONO
CVE-2025-4643MEDIUM
Payload uses JSON Web Tokens (JWT) for authentication. After log out JWT is not invalidated, which allows an attacker who has stolen or intercepted token to freely reuse it until e
Aug 29, 20256.321NONO
CVE-2023-30843MEDIUM
Payload is a free and open source headless content management system. In versions prior to 1.7.0, if a user has access to documents that contain hidden fields or fields they do not
Apr 26, 20236.521NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
54%
23%
23%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network13 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (92.3%)
High1 (7.7%)
Unknown0 (0.0%)
User Interaction
None9 (69.2%)
Unknown0 (0.0%)
Required3 (23.1%)
Privileges Required
Low5 (38.5%)
High1 (7.7%)
None7 (53.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Payloadcms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Payloadcms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Payloadcms's Products

View all 3 CNAs →

Top CWEs