CVE-2026-34747

Published
View on NVD ↗
CVSS v3
8.5
HIGH
CVSS v2
N/A
Affected
1
PROJECT

Description

Payload is a free and open source headless content management system. Prior to version 3.79.1, certain request inputs were not properly validated. An attacker could craft requests that influence SQL query execution, potentially exposing or modifying data in collections. This issue has been patched in version 3.79.1.

Payload is the open-source, fullstack Next.js framework, giving you instant backend superpowers. Get a full TypeScript backend and admin panel instantly. Use Payload as a headless CMS or for building powerful applications.
GitHubGitHub
43.2K