90%
Total Score
99
100
100
100
50
| Title | Versions | Severity |
|---|---|---|
CVE-2026-34748 @payloadcms/next is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 3.78.0. | 0.0.0 - 3.78.0 | High |
AIKIDO-2025-10199 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @payloadcms/next is vulnerable to Open Redirect in versions 3.31.0 - 3.31.0. | 3.31.0 - 3.31.0 | Medium |
AIKIDO-2025-10186 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @payloadcms/next is vulnerable to Open Redirect in versions 3.0.0 - 3.30.0. | 3.0.0 - 3.30.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
sass Version 1.77.4 | — | — |
uuid Version 11.1.0 | — | — |
busboy Version ^1.6.0 | — | — |
dequal Version 2.0.3 | — | — |
qs-esm Version 8.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant