Vulnerabilities/

@payloadcms/next has Stored XSS in Admin Panel

Severity:
High

Description

A stored Cross-site Scripting (XSS) vulnerability existed in the admin panel. An authenticated user with write access to a collection could save content that, when viewed by another user, would execute in their browser.

Recommendation

Update the @payloadcms/next package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@payloadcms/next
Anything's wrong? Let us know Last updated on April 06, 2026