Tag
medium
advisory
Payload CMS SSRF Vulnerability (CVE-2026-34746)
2 rules 1 TTP 1 CVEPayload CMS versions before 3.79.1 are vulnerable to Server-Side Request Forgery (SSRF) allowing authenticated users with upload access to trigger outbound HTTP requests to arbitrary URLs.
cve-2026-34746
ssrf
payload-cms
2r
1t
1c
critical
advisory
Payload CMS Password Reset Vulnerability (CVE-2026-34751)
2 rules 1 TTP 1 CVE 1 IOCAn unauthenticated attacker can perform actions on behalf of a user initiating a password reset in Payload CMS versions prior to 3.79.1 due to a flaw in the password recovery flow, potentially leading to account takeover or privilege escalation.
cve-2026-34751
payload-cms
password-reset
vulnerability
2r
1t
1c
1i