Security

Vulnerabilities

Real-time alerts of vulnerabilities across monitored open-source ecosystems.

Ecosystems covered

1

Npm

Total vulnerabilities tracked

24

From global vulnerability databases

Exclude malware
Package payload

5.2

Medium

Ecosystem: Npm

Package: @t-in-one/only_difference_payload

9.1

Critical

Ecosystem: Npm

Package: @delmaredigital/payload-puck

3.8

Low

Ecosystem: Npm

Package: @payloadcms/storage-r2

FLAT-NNRB7 (CVE-2026-34749)

Cross-site request forgery In payload

0.6

Low

Ecosystem: Npm

Package: payload

3.9

Low

Ecosystem: Npm

Package: payload

5.7

Medium

Ecosystem: Npm

Package: @payloadcms/next

FLAT-AWNC1 (CVE-2026-34747)

SQL injection - Code In payload

7.8

High

Ecosystem: Npm

Package: payload

8.9

High

Ecosystem: Npm

Package: @payloadcms/graphql

3.9

Low

Ecosystem: Npm

Package: payload

FLAT-UDEXX (CVE-2026-25574)

Restricted fields manipulation In payload

0.6

Low

Ecosystem: Npm

Package: payload

8.1

High

Ecosystem: Npm

Package: @payloadcms/drizzle

5.2

Medium

Ecosystem: Npm

Package: xss-payload-7n-ctf

5.2

Medium

Ecosystem: Npm

Package: xss-payload-all

FLAT-X6NGM (CVE-2025-4644)

Session Fixation In @payloadcms/next

1.3

Low

Ecosystem: Npm

Package: @payloadcms/next

1.7

Low

Ecosystem: Npm

Package: @payloadcms/graphql

5.2

Medium

Ecosystem: Npm

Package: kkyun-xss-payload

5.2

Medium

Ecosystem: Npm

Package: jun-xss-payload

5.2

Medium

Ecosystem: Npm

Package: monpayload

5.2

Medium

Ecosystem: Npm

Package: @b10902118/note-xss-payload

5.2

Medium

Ecosystem: Npm

Package: zora-exploit-payload

5.2

Medium

Ecosystem: Npm

Package: payload_package123

5.2

Medium

Ecosystem: Npm

Package: payload_package1

FLAT-QZOIK (CVE-2023-30843)

Business information leak In payload

6.9

Medium

Ecosystem: Npm

Package: payload

FLAT-BGRD4 (CVE-2022-27952)

Insecure file upload In payload

8.1

High

Ecosystem: Npm

Package: payload