payload
28 known vulnerabilities · 2 critical · 6 high
Hidden fields can be leaked on readable collections in Payload
Payload has Authenticated SSRF via Upload Functionality
payload-preferences has Cross-Collection IDOR in Access Control (Multi-Auth Environments)
Payload: Pre-Authentication Account Takeover via Parameter Injection in Password Recovery
Payload: Server-Side Request Forgery (SSRF) in External File URL Uploads
Payload has a CSRF Protection Bypass in Authentication Flow
Payload has an SQL Injection via Query Handling
Unrestricted Upload of File with Dangerous Type in Payload
OpenClaw: Node camera URL payload host-binding bypass allowed gateway fetch pivots
grunt-util-property 0.0.2 function call can add/modify properties of Object.prototype using a __proto__ payload
Denial of Service vulnerability with large JSON payloads in fastify
Vite XSS vulnerability in `server.transformIndexHtml` via URL payload
tagify can pass a malicious placeholder to initiate the cross-site scripting (XSS) payload
OpenClaw's tools.exec.safeBins generic fallback allowed interpreter-style inline payload execution in allowlist mode
OpenClaw: system.run allow-always persistence included shell-commented payload tails
@payloadcms/next has Stored XSS in Admin Panel
Duplicate Advisory: OpenClaw: Node-host approvals could show misleading shell payloads instead of the executed argv
Payload has Insufficient Filename Validation in Client-Upload Signed-URL Endpoints
OpenClaw: Authenticated `/hooks/wake` and mapped `wake` payloads are promoted into the trusted `System:` prompt channel
OpenClaw: Node-host approvals could show misleading shell payloads instead of the executed argv
Raneto Denial of Service via crafted payload injected into `Search` parameter
@payloadcms/drizzle has SQL Injection in JSON/RichText Queries on PostgreSQL/SQLite Adapters
@delmaredigital/payload-puc is missing authorization on /api/puck/* CRUD endpoints allows unauthenticated access to Puck-registered collections
OpenClaw: QQ Bot structured payloads could read arbitrary local files
Malicious code in zora-exploit-payload (npm)