CVE-2026-34748Disclosure(payloadcms / payload)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch payloadcms payload systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/next, a stored Cross-Site Scripting (XSS) vulnerability existed in the admin panel. An authenticated user with write access to a collection could save content that, when viewed by another user, would execute in their browser. This issue has been patched in version 3.78.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • payload

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 3 classified signals
  • Peaked 3d ago at 5 mentions (2026-04-02); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
payload

Deep dive

Activity timeline8 mentions / 4d
01345Mentions · 2026-04-02: 5Mentions · 2026-04-14: 1Mentions · 2026-05-14: 1Mentions · 2026-08-27: 1Patch / Workaround · 2026-04-02: 2Patch / Workaround · 2026-04-14: 1Technical Details · 2026-04-02: 4Technical Details · 2026-04-14: 104-0204-1405-1408-27
Signal classification3 categories
Disclosure
337.5%
General
337.5%
Patch
225.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-025
Disclosure3General1Patch1
2026-04-141
Patch1
2026-05-141
General1
2026-08-271
General1
Full discourse8 posts
  • BugBunny.ai - Continuous AI Pentesting System@BugBunny_ai
    General

    66 CVE-2025-58434 CVE-2025-59057 CVE-2025-59790 CVE-2025-59792 CVE-2025-61622 CVE-2025-61686 CVE-2025-64756 CVE-2026-21884 CVE-2026-22807 CVE-2026-23630 CVE-2026-27471 CVE-2026-27806 CVE-2026-27955 CVE-2026-28215 CVE-2026-28217 CVE-2026-28351 CVE-2026-28361 CVE-2026-28384 CVE-2026-28396 CVE-2026-28398 CVE-2026-28444 CVE-2026-28445 CVE-2026-29093 CVE-2026-30973 CVE-2026-31888 CVE-2026-33016 CVE-2026-33037 CVE-2026-33038 CVE-2026-33039 CVE-2026-3351 CVE-2026-34037 CVE-2026-34158 CVE-2026-34167 CVE-2026-34170 CVE-2026-34171 CVE-2026-34198 CVE-2026-34532 CVE-2026-34573 CVE-2026-34574 CVE-2026-34595 CVE-2026-34746 CVE-2026-34748 CVE-2026-34749 CVE-2026-34750 CVE-2026-34972 CVE-2026-35214 CVE-2026-35412 CVE-2026-35413 CVE-2026-35441 CVE-2026-40165 CVE-2026-40293 CVE-2026-40302 CVE-2026-40304 CVE-2026-40454 CVE-2026-40914 CVE-2026-41131 CVE-2026-41590 CVE-2026-42883 CVE-2026-42884 CVE-2026-42885 CVE-2026-42886 CVE-2026-43888 CVE-2026-43889 CVE-2026-43998 CVE-2026-43999 CVE-2026-4800

    Post summary

    A list of CVE identifiers is provided with no additional context regarding exploitation, patches, or technical details.

    2176862729382.1K
    3.1K followersView on X
  • BugBunny.ai - Continuous AI Pentesting System@BugBunny_ai
    General

    108 CVE-2025-58434 CVE-2025-59057 CVE-2025-59343 CVE-2025-59790 CVE-2025-59792 CVE-2025-61622 CVE-2025-61686 CVE-2025-62228 CVE-2025-62232 CVE-2025-64756 CVE-2026-21884 CVE-2026-22706 CVE-2026-22807 CVE-2026-23630 CVE-2026-24015 CVE-2026-24899 CVE-2026-27471 CVE-2026-27806 CVE-2026-27955 CVE-2026-28215 CVE-2026-28217 CVE-2026-28351 CVE-2026-28361 CVE-2026-28384 CVE-2026-28396 CVE-2026-28398 CVE-2026-28444 CVE-2026-28445 CVE-2026-29093 CVE-2026-30973 CVE-2026-31888 CVE-2026-33016 CVE-2026-33037 CVE-2026-33038 CVE-2026-33039 CVE-2026-33264 CVE-2026-33413 CVE-2026-3351 CVE-2026-34037 CVE-2026-34158 CVE-2026-34167 CVE-2026-34170 CVE-2026-34171 CVE-2026-34198 CVE-2026-34532 CVE-2026-34573 CVE-2026-34574 CVE-2026-34595 CVE-2026-34746 CVE-2026-34748 CVE-2026-34749 CVE-2026-34750 CVE-2026-34972 CVE-2026-35214 CVE-2026-35412 CVE-2026-35413 CVE-2026-35441 CVE-2026-40006 CVE-2026-40007 CVE-2026-40009 CVE-2026-40165 CVE-2026-40293 CVE-2026-40302 CVE-2026-40304 CVE-2026-40452 CVE-2026-40454 CVE-2026-40914 CVE-2026-41131 CVE-2026-41590 CVE-2026-42275 CVE-2026-42883 CVE-2026-42884 CVE-2026-42885 CVE-2026-42886 CVE-2026-43888 CVE-2026-43889 CVE-2026-43998 CVE-2026-43999 CVE-2026-44247 CVE-2026-44309 CVE-2026-44310 CVE-2026-44442 CVE-2026-44446 CVE-2026-44705 CVE-2026-44947 CVE-2026-45022 CVE-2026-45090 CVE-2026-45720 CVE-2026-45723 CVE-2026-45726 CVE-2026-46553 CVE-2026-46554 CVE-2026-47733 CVE-2026-4800 CVE-2026-48978 CVE-2026-49478 CVE-2026-50285 CVE-2026-52808 CVE-2026-52809 CVE-2026-53926 CVE-2026-53928 CVE-2026-53929 CVE-2026-53930 CVE-2026-56842 CVE-2026-60076 CVE-2026-60077 CVE-2026-75605 CVE-2026-9103

    Post summary

    The post is simply a list of CVE identifiers, providing no context, details, or analysis about the vulnerabilities.

    30124138.4K
    4.0K followersView on X
  • BugBunny.ai - Vibehacking for Vibecoders@BugBunny_ai
    General

    + CVE-2026-34746 where's the 47?? 😅 CVE-2026-34748 CVE-2026-34749 CVE-2026-34750 CVE-2026-34532 CVE-2026-34573 CVE-2026-34574 CVE-2026-34595 bunny collected 43 CVEs 🚀

    Post summary

    The message merely enumerates a series of CVE identifiers without providing any additional context, technical details, or evidence of exploitation or mitigation.

    3001431.5K
    2.7K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-34748 Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/next, a stored Cross-Site Scripting (XSS) vulnerability e… https://www.cve.org/CVERecord?id=CVE-2026-34748

    Post summary

    The post discloses a stored XSS issue in Payload CMS (CVE‑2026‑34748) prior to v3.78.0, points to the CVE record, but does not provide a PoC, exploit code, or evidence of active exploitation.

    00022314
    57.6K followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 HIGH: CVE-2026-34748 (CVSS 8.7) - Stored XSS in Payload CMS admin panel (@payloadcms/next <3.78.0). Authenticated users can inject malicious content. Patch to 3.78.0 immediately. #CVE #PatchNow #ThreatIntel https://t.co/PfjWHBoqap

    Post summary

    CVE-2026‑34748 is a stored XSS flaw (CVSS 8.7) in Payload CMS’s admin panel, and users are urged to update to 3.78.0 immediately.

    0000043
    25 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-34748: HIGH] Critical stored XSS vulnerability in Payload CMS admin panel in versions earlier than 3.78.0. Update to the latest version to ensure security against potential attacks.#cve,CVE-2026-34748,#cybersecurity https://cvefind.com/CVE-2026-34748

    Post summary

    The tweet alerts to a high‑severity stored XSS flaw in Payload CMS admin panels prior to version 3.78.0 and recommends updating to the latest release to patch the issue.

    0000038
    617 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-34748 Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/next, a stored Cross-Site Scripting (XSS) vulnerability e… https://www.cve.org/CVERecord?id=CVE-2026-34748 ----- Traducción: CVE-2026-34748 Pay… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑34748, describing a stored XSS flaw in Payload CMS before version 3.78.0, and provides a link to the official CVE record.

    0000033
    65 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-34748 - High Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/next, a stored Cross-Site Scripting (XSS) vulnerability existed in the admin panel... https://www.thehackerwire.com/vulnerability/CVE-2026-34748/ https://t.co/GTztFB8AKD

    Post summary

    The tweet announces CVE-2026-34748, a stored XSS flaw in Payload CMS admin panel versions before 3.78.0.

    0000047
    163 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppayloadcmspayload-node.js-

Explore more