Description
A stored Cross-site Scripting (XSS) vulnerability existed in the admin panel. An authenticated user with write access to a collection could save content that, when viewed by another user, would execute in their browser.
Recommendation
Update the @payloadcms/next package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.78.0
- Patched version(s): 3.78.0
References
Related Issues
- NotChatbot WebChat has a stored cross-site scripting (XSS) vulnerability - CVE-2026-30048
- Open WebUI has Stored XSS in Banner Component via Improper Sanitization Order - CVE-2026-45665
- Trix has a Stored XSS vulnerability through serialized attributes - CVE-2026-73426
- PostCSS has XSS via Unescaped </style> in its CSS Stringify Output - CVE-2026-41305
You might also like:
- Tags:
- npm
- @payloadcms/next
Anything's wrong? Let us know Last updated on April 06, 2026


