OSS Support Hub / CMS

Node.js CMS MIT Latest: v3.84.1

Payload CMS

The most powerful TypeScript-first headless CMS

Project Health at a Glance

Live data from GitHub and npm, updated daily.

42.4K
GitHub Stars
📦
v3.84.1
Latest Release · 23 days ago
🔄
6d
Avg. Release Cadence
🐛
729
Open Issues
📅
Today
Last Commit
⬇️
400.3K
Weekly Downloads
🔒
10
Active CVEs

Data last fetched: 2026-05-16

Known Vulnerabilities

10 active CVEs reported via OSV.dev

Payload's SQLite adapter Session Fixation vulnerability

Published: 2025-08-29 Fixed in: 3.44.0

Hidden fields can be leaked on readable collections in Payload

Published: 2023-04-26 Fixed in: 1.7.0

Payload does not invalidate JWTs after log out

Published: 2025-08-29 Fixed in: 3.44.0

Payload has Authenticated SSRF via Upload Functionality

Published: 2026-04-01 Fixed in: 3.79.1

Payload has an SQL Injection via Query Handling

Published: 2026-04-01 Fixed in: 3.79.1

Payload: Server-Side Request Forgery (SSRF) in External File URL Uploads

Published: 2026-02-24 Fixed in: 3.75.0

Payload: Pre-Authentication Account Takeover via Parameter Injection in Password Recovery

Published: 2026-04-01 Fixed in: 3.79.1

payload-preferences has Cross-Collection IDOR in Access Control (Multi-Auth Environments)

Published: 2026-02-05 Fixed in: 3.74.0

Payload has a CSRF Protection Bypass in Authentication Flow

Published: 2026-04-01 Fixed in: 3.79.1

Unrestricted Upload of File with Dangerous Type in Payload

Published: 2022-04-13 Fixed in: 0.15.1

Alternatives to Payload CMS

Other CMS projects in the Node.js ecosystem worth evaluating.

Support Options for Payload CMS

Enterprise Support via DepKeep

Get SLA-backed support, security patches, and direct access to senior engineers for Payload CMS — without relying on volunteer maintainers.

Talk to an Expert →