Description
A stored Cross-site Scripting (XSS) vulnerability existed in the admin panel. An authenticated user with write access to a collection could save content that, when viewed by another user, would execute in their browser.
Recommendation
Update the @payloadcms/next package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.78.0
- Patched version(s): 3.78.0
References
Could your website be exposed too?
SmartScanner can check your website for @payloadcms/next has Stored XSS in Admin Panel and gives you actionable findings to investigate.
Start a free scanRelated Issues
- NotChatbot WebChat has a stored cross-site scripting (XSS) vulnerability - CVE-2026-30048
- Open WebUI has Stored XSS in Banner Component via Improper Sanitization Order - CVE-2026-45665
- Trix has a Stored XSS vulnerability through serialized attributes - CVE-2026-73426
- PostCSS has XSS via Unescaped </style> in its CSS Stringify Output - CVE-2026-41305


