Known Vulnerabilities for Payload by Payloadcms
Listed below are 7 of the newest known vulnerabilities associated with "Payload" by "Payloadcms".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-56422 json | Multiple MISP core controllers and model capture paths accepted client-controlled request fields such as primary keys (id) an... | Not Provided | 2026-06-22 | 2026-06-22 |
| CVE-2026-55740 json | Nur-Alam39 bus-ticket (no released versions; latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7bad) contains an unauthentica... | Not Provided | 2026-06-18 | 2026-06-18 |
| CVE-2026-54393 json | A stored cross-site scripting vulnerability exists in MISP when the Overmind theme is used. The setHomePage endpoint previous... | Not Provided | 2026-06-12 | 2026-06-15 |
| CVE-2026-54386 json | marimo before 0.23.9 contains a reflected cross-site scripting vulnerability in the notebook page that allows unauthenticated... | Not Provided | 2026-06-17 | 2026-06-18 |
| CVE-2026-54341 json | Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.39.0, a crafted RESTORE payload trigg... | Not Provided | 2026-06-26 | 2026-06-26 |
| CVE-2026-54308 json | n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, the MicrosoftAgent365Trigger and StripeTrigge... | Not Provided | 2026-06-23 | 2026-06-24 |
| CVE-2026-54306 json | n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, a prototype pollution vulnerability allowed a... | Not Provided | 2026-06-23 | 2026-06-26 |
| CVE-2026-54288 json | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, the Body Limit Middle... | Not Provided | 2026-06-22 | 2026-06-23 |
| CVE-2026-54280 json | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not cl... | Not Provided | 2026-06-22 | 2026-06-22 |
| CVE-2026-54278 json | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possibl... | Not Provided | 2026-06-22 | 2026-06-23 |