Live data from GitHub and npm, updated daily.
Data last fetched: 2026-05-16
10 active CVEs reported via OSV.dev
Payload's SQLite adapter Session Fixation vulnerability
Hidden fields can be leaked on readable collections in Payload
Payload does not invalidate JWTs after log out
Payload has Authenticated SSRF via Upload Functionality
Payload has an SQL Injection via Query Handling
Payload: Server-Side Request Forgery (SSRF) in External File URL Uploads
Payload: Pre-Authentication Account Takeover via Parameter Injection in Password Recovery
payload-preferences has Cross-Collection IDOR in Access Control (Multi-Auth Environments)
Payload has a CSRF Protection Bypass in Authentication Flow
Unrestricted Upload of File with Dangerous Type in Payload
Other CMS projects in the Node.js ecosystem worth evaluating.
Get SLA-backed support, security patches, and direct access to senior engineers for Payload CMS — without relying on volunteer maintainers.
Talk to an Expert →