CVE-2026-34748: Payloadcms Payload
High severity, CVSS 8.7. EPSS: 0.4% chance of exploitation in the next 30 days.
Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/next, a stored Cross-Site Scripting (XSS) vulnerability existed in the admin panel. An authenticated user with write access to a collection could save content that, when viewed by another user, would execute in their browser. This issue has been patched in version 3.78.0.
Affected products
- Payloadcms Payload: before 3.78.0 (fixed in 3.78.0)
Published 2026-04-01. Last modified 2026-06-17.