High severity8.7NVD Advisory· Published Apr 1, 2026· Updated Apr 13, 2026
CVE-2026-34748
CVE-2026-34748
Description
Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/next, a stored Cross-Site Scripting (XSS) vulnerability existed in the admin panel. An authenticated user with write access to a collection could save content that, when viewed by another user, would execute in their browser. This issue has been patched in version 3.78.0.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@payloadcms/nextnpm | < 3.78.0 | 3.78.0 |
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/advisories/GHSA-mmxc-95ch-2j7cghsaADVISORY
- github.com/payloadcms/payload/security/advisories/GHSA-mmxc-95ch-2j7cnvdMitigationVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-34748ghsaADVISORY
News mentions
50- Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout SkimmingThe Hacker News · May 16, 2026
- Funnel Builder WordPress plugin bug exploited to steal credit cardsBleepingComputer · May 15, 2026
- Metasploit Wrap-Up 05/15/2026Rapid7 Blog · May 15, 2026
- In Other News: Big Tech vs Canada Encryption Bill, Cisco’s Free AI Security Spec, Audi App FlawsSecurityWeek · May 15, 2026
- Gremlin Stealer Evolves into Modular Threat with Advanced Evasion CapabilitiesInfosecurity Magazine · May 15, 2026
- Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource FilesUnit 42 · May 15, 2026
- China-Linked Hackers Deploy New TencShell Malware Against Global ManufacturerInfosecurity Magazine · May 15, 2026
- Stealer Backdoor Found in 3 Node-IPC Versions Targeting Developer SecretsThe Hacker News · May 14, 2026
- 'FrostyNeighbor' APT Carefully Targets Govt Orgs in Poland, UkraineDark Reading · May 14, 2026
- ThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ StoriesThe Hacker News · May 14, 2026
- Cyber-Enabled Cargo Crime: How Cybercrime Tradecraft is Used to Steal FreightBleepingComputer · May 14, 2026
- Mustang Panda Linked to Updated FDMTP Backdoor in Asia-Pacific Espionage CampaignInfosecurity Magazine · May 14, 2026
- Ghostwriter Targets Ukrainian Government With Geofenced PDF Phishing, Cobalt StrikeThe Hacker News · May 14, 2026
- New Fragnesia Flaw Hands Linux Local Users Root AccessInfosecurity Magazine · May 14, 2026
- Chinese APTs Expand Targets, Update Backdoors in Recent CampaignsSecurityWeek · May 14, 2026
- Kimsuky targets organizations with PebbleDash-based toolsSecurelist · May 14, 2026
- FrostyNeighbor: Fresh mischief and digital shenanigansESET WeLiveSecurity · May 14, 2026
- New Fragnesia Linux Kernel LPE Grants Root Access via Page Cache CorruptionThe Hacker News · May 14, 2026
- Vector embedding security gap exposes enterprise AI pipelinesHelp Net Security · May 14, 2026
- Attackers Weaponize RubyGems for Data Dead DropsDark Reading · May 13, 2026
- When IT Support Calls: Dissecting a ModeloRAT Campaign from Teams to Domain CompromiseRapid7 Blog · May 13, 2026
- China's 'FamousSparrow' APT Nests in South Caucasus Energy FirmDark Reading · May 13, 2026
- Azerbaijani Energy Firm Hit by Repeated Microsoft Exchange ExploitationThe Hacker News · May 13, 2026
- GemStuffer Abuses 150+ RubyGems to Exfiltrate Scraped U.K. Council Portal DataThe Hacker News · May 13, 2026
- Fake Claude search results lure Mac users into ClickFix attackMalwarebytes Labs · May 12, 2026
- Mini Shai-Hulud Hits TanStack npm PackagesInfosecurity Magazine · May 12, 2026
- Free OnlyFans Lure Used to Spread Cross-Platform CRPx0 MalwareSecurityWeek · May 12, 2026
- 20 Leaders Who Built the CISO Era: 2 Decades of ChangeDark Reading · May 12, 2026
- Cache-poisoning caper turns TanStack npm packages toxicThe Register Security · May 12, 2026
- Attackers Combine ClickFix With PySoxy Proxying to Maintain PersistenceInfosecurity Magazine · May 12, 2026
- Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More PackagesThe Hacker News · May 12, 2026
- Shai Hulud attack ships signed malicious TanStack, Mistral npm packagesBleepingComputer · May 12, 2026
- Is the SOC Obsolete, and We Just Haven’t Admitted It Yet?SecurityWeek · May 12, 2026
- TanStack, Mistral AI, UiPath Hit in Fresh Supply Chain AttackSecurityWeek · May 12, 2026
- State-sponsored actors, better known as the friends you don’t wantCisco Talos Intelligence · May 12, 2026
- Malicious Hugging Face Repository Typosquats OpenAIInfosecurity Magazine · May 12, 2026
- Cookie thieves caught stealing dev secrets via fake Claude Code installersThe Register Security · May 11, 2026
- Tech Can't Stop These Threats — Your People CanDark Reading · May 11, 2026
- Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass ExploitationThe Hacker News · May 11, 2026
- Google researchers uncover criminal zero-day exploit likely built with AIHelp Net Security · May 11, 2026
- ⚡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and MoreThe Hacker News · May 11, 2026
- Hackers abuse Google ads, Claude.ai chats to push Mac malwareBleepingComputer · May 10, 2026
- JDownloader site hacked to replace installers with Python RAT malwareBleepingComputer · May 9, 2026
- Fake OpenAI repository on Hugging Face pushes infostealer malwareBleepingComputer · May 9, 2026
- Metasploit Wrap-Up 05/08/2026Rapid7 Blog · May 8, 2026
- TCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook WormsThe Hacker News · May 8, 2026
- Zero Chaos: Scaling Detection Engineering at the Speed of Software, with Detection As CodeRapid7 Blog · May 8, 2026
- New TCLBanker malware self-spreads over WhatsApp and OutlookBleepingComputer · May 7, 2026
- Unplug your way to better codeCisco Talos Intelligence · May 7, 2026
- PCPJack Credential Stealer Exploits 5 CVEs to Spread Worm-Like Across Cloud SystemsThe Hacker News · May 7, 2026