Payload CMS is a headless content-management system focused on a single product line, yet occupies a prominent position among web-application platforms. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur across durable weakness classes including SQL injection, server-side request forgery, authorization bypass, cross-site request forgery, and sensitive-information exposure—patterns characteristic of web-application input handling and access-control enforcement in database-driven content platforms. Defenders should prioritize tracking this vendor's security advisories and apply patches promptly to internet-reachable instances; current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Payloadcms over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-34751CRITICAL Payload is a free and open source headless content management system. Prior to version 3.79.1 in @payloadcms/graphql and payload, a vulnerability in the password recovery flow coul | Apr 1, 2026 | 9.1 | 32 | NO | NO |
CVE-2026-25544CRITICAL Payload is a free and open source headless content management system. Prior to 3.73.0, when querying JSON or richText fields, user input was directly embedded into SQL without esca | Feb 6, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-34748HIGH Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/next, a stored Cross-Site Scripting (XSS) vulnerability existed in the | Apr 1, 2026 | 8.7 | 31 | NO | NO |
CVE-2026-34747HIGH Payload is a free and open source headless content management system. Prior to version 3.79.1, certain request inputs were not properly validated. An attacker could craft requests | Apr 1, 2026 | 8.2 | 29 | NO | NO |
CVE-2026-34746HIGH Payload is a free and open source headless content management system. Prior to version 3.79.1, an authenticated Server-Side Request Forgery (SSRF) vulnerability exists in the uploa | Apr 1, 2026 | 7.7 | 27 | NO | NO |
CVE-2022-27952CRITICAL An arbitrary file upload vulnerability in the file upload module of PayloadCMS v0.15.0 allows attackers to execute arbitrary code via a crafted SVG file. | Apr 12, 2022 | 9.8 | 24 | NO | NO |
CVE-2026-34750MEDIUM Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/storage-azure, @payloadcms/storage-gcs, @payloadcms/storage-r2, and @pa | Apr 1, 2026 | 6.5 | 23 | NO | NO |
CVE-2026-34749MEDIUM Payload is a free and open source headless content management system. Prior to version 3.79.1, a Cross-Site Request Forgery (CSRF) vulnerability exists in the authentication flow. | Apr 1, 2026 | 5.4 | 21 | NO | NO |
CVE-2025-4643MEDIUM Payload uses JSON Web Tokens (JWT) for authentication. After log out JWT is not invalidated, which allows an attacker who has stolen or intercepted token to freely reuse it until e | Aug 29, 2025 | 6.3 | 21 | NO | NO |
CVE-2023-30843MEDIUM Payload is a free and open source headless content management system. In versions prior to 1.7.0, if a user has access to documents that contain hidden fields or fields they do not | Apr 26, 2023 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Payloadcms.
Media articles that mention a CVE ID that affects a product developed by Payloadcms — matched by CVE ID, not by vendor name.