CVE-2026-34747Disclosure(payloadcms / payload)

LOWCVSS 8.2 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch payloadcms payload systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Payload is a free and open source headless content management system. Prior to version 3.79.1, certain request inputs were not properly validated. An attacker could craft requests that influence SQL query execution, potentially exposing or modifying data in collections. This issue has been patched in version 3.79.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • payload

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
payload

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-04-02: 4Patch / Workaround · 2026-04-02: 1Technical Details · 2026-04-02: 404-02
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-34747 Payload is a free and open source headless content management system. Prior to version 3.79.1, certain request inputs were not properly validated. An attacker could c… https://www.cve.org/CVERecord?id=CVE-2026-34747 ----- Traducción: CVE-2026-34747 Pay… http://infoflow.cloud`

    Post summary

    The post briefly announces CVE-2026-34747, noting an input‑validation issue in a CMS before version 3.79.1, but it provides no exploit code, PoC, patch, or evidence of real‑world attacks.

    0000039
    65 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34747 Payload is a free and open source headless content management system. Prior to version 3.79.1, certain request inputs were not properly validated. An attacker could c… https://www.cve.org/CVERecord?id=CVE-2026-34747

    Post summary

    The post announces CVE-2026-34747, noting that prior to v3.79.1 some request inputs lacked proper validation, but it provides no PoC, exploit, patch, or evidence of active attack.

    00000159
    56.9K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-34747: HIGH] Cyber security alert! Update to Payload 3.79.1 now. Earlier versions vulnerable to SQL injection, risking data exposure. Patched in latest release for protection.#cve,CVE-2026-34747,#cybersecurity https://cvefind.com/CVE-2026-34747

    Post summary

    The post announces that CVE-2026-34747, a SQL injection vulnerability, has been fixed in Payload 3.79.1, urging users to apply the update.

    0000036
    617 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-34747 - High Payload is a free and open source headless content management system. Prior to version 3.79.1, certain request inputs were not properly validated. An attacker could craft requests that influe... https://www.thehackerwire.com/vulnerability/CVE-2026-34747/ https://t.co/qOg2Fv0zYT

    Post summary

    The message announces CVE-2026-34747, identifies an input validation weakness in a CMS prior to version 3.79.1, and links to a source for more details.

    0000047
    163 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppayloadcmspayload-node.js-

Explore more