Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/payload

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

The @payloadcms/storage-vercel-blob storage adapter for Payload contains an improper access control vulnerability that allows authenticated users to bypass collection-level permissions by accessing the client-upload route directly. Attackers can upload files through the client-upload endpoint without possessing the required collection access permissions, circumventing the intended access control enforcement.

Join the discussion

Payload is a free and open source headless content management system. Prior to 3.73.0, when querying JSON or richText fields, user input was directly embedded into SQL without escaping, enabling blind SQL injection attacks. An unauthenticated attacker could extract sensitive data (emails, password reset tokens) and achieve full account takeover without password cracking. This vulnerability is fixed in 3.73.0.

Join the discussion

PayloadCMS version 3.84.1 contains an improper authorization vulnerability related to insufficient access control on the account unlock operation. This weakness could allow unauthorized users with limited privileges to unlock accounts without proper authorization checks. The vulnerability is classified under CWE-307, indicating issues with insufficient authorization. No known exploits are reported in the wild, and no patch or remediation has been documented yet.

Join the discussion

PayloadCMS versions prior to 3.78.0 contain a path traversal vulnerability in the client-upload signed-URL endpoints for multiple storage backends (S3, GCS, Azure, R2). This vulnerability allows an attacker to craft filenames that escape the intended storage directory, potentially leading to unauthorized file placement. The issue has been patched in version 3.78.0. The vulnerability has a CVSS score of 6.5, indicating a medium severity level.

Join the discussion

Payload is a free and open source headless content management system. Prior to version 3.79.1, a Cross-Site Request Forgery (CSRF) vulnerability exists in the authentication flow. Under certain conditions, the configured CSRF protection could be bypassed, allowing cross-site requests to be made. This issue has been patched in version 3.79.1.

Join the discussion

A stored Cross-Site Scripting (XSS) vulnerability exists in the admin panel of Payload CMS versions prior to 3.78.0. An authenticated user with write access to a collection could save malicious content that executes in the browser of another user viewing that content. This vulnerability has been patched in version 3.78.0.

Join the discussion

Payload is a free and open source headless content management system. Prior to version 3.79.1, certain request inputs were not properly validated. An attacker could craft requests that influence SQL query execution, potentially exposing or modifying data in collections. This issue has been patched in version 3.79.1.

Join the discussion

PayloadCMS versions prior to 3.79.1 contain an authenticated Server-Side Request Forgery (SSRF) vulnerability in the upload functionality. Authenticated users with create or update permissions on upload-enabled collections can cause the server to make arbitrary outbound HTTP requests. This vulnerability has been addressed in version 3.79.1. The CVSS score is 7.7, indicating high severity due to the potential for server-side request manipulation without impacting data integrity or availability directly.

Join the discussion

Payload is a free and open source headless content management system. Prior to 3.75.0, a Server-Side Request Forgery (SSRF) vulnerability exists in Payload's external file upload functionality. When processing external URLs for file uploads, insufficient validation of HTTP redirects could allow an authenticated attacker to access internal network resources. The Payload environment must have at least one collection with `upload` enabled and a user who has `create` access to that upload-enabled collection in order to be vulnerable. An authenticated user with upload collection write permissions could potentially access internal services. Response content from internal services could be retrieved through the application. This vulnerability has been patched in v3.75.0. As a workaround, one may mitigate this vulnerability by disabling external file uploads via the `disableExternalFile` upload collection option, or by restricting `create` access on upload-enabled collections to trusted users only.

Join the discussion

Payload is a free and open source headless content management system. Prior to 3.74.0, a cross-collection Insecure Direct Object Reference (IDOR) vulnerability exists in the payload-preferences internal collection. In multi-auth collection environments using Postgres or SQLite with default serial/auto-increment IDs, authenticated users from one auth collection can read and delete preferences belonging to users in different auth collections when their numeric IDs collide. This vulnerability has been patched in v3.74.0.

Join the discussion

Showing 1 to 10 of 10 results

Filters:Package: pkg:github/payload
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses