📦 Payload

by Payloadcms

🔍 What is Payload?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-25544

CRITICAL CVSS 9.8 Feb 6, 2026

This is a critical SQL injection vulnerability in Payload CMS versions before 3.73.0 that allows unauthenticated attackers to extract sensitive data and achieve full account takeover. The vulnerabilit...

CVE-2022-27952

CRITICAL CVSS 9.8 Apr 12, 2022

CVE-2022-27952 is a critical arbitrary file upload vulnerability in PayloadCMS v0.15.0 that allows attackers to upload malicious SVG files containing embedded code. This enables remote code execution ...

CVE-2026-27567

MEDIUM CVSS 6.5 Feb 24, 2026

Payload CMS versions before 3.75.0 contain a Server-Side Request Forgery (SSRF) vulnerability in external file upload functionality. Authenticated users with upload permissions can exploit insufficien...

CVE-2026-25574

MEDIUM CVSS 5.4 Feb 6, 2026

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Payload CMS where authenticated users from one authentication collection can read and delete preferences belonging to use...