11 Total advisories
11 Vulnerabilities
0 Malware
Dependency scanning
Check whether payload is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.4
CVE-2023-30843
Hidden fields can be leaked on readable collections in Payload
UNKNOWN
CVE-2026-11779
Payload CMS default account-unlock access allows authenticated users to reset other accounts' lockouts
CRITICAL 9.1
CVE-2026-34751
Payload: Pre-Authentication Account Takeover via Parameter Injection in Password Recovery
HIGH 8.5
CVE-2026-34747
Payload has an SQL Injection via Query Handling
HIGH 7.7
CVE-2026-34746
Payload has Authenticated SSRF via Upload Functionality
MEDIUM 5.4
CVE-2026-34749
Payload has a CSRF Protection Bypass in Authentication Flow
MEDIUM 6.5
CVE-2026-27567
Payload: Server-Side Request Forgery (SSRF) in External File URL Uploads
MEDIUM 5.4
CVE-2026-25574
payload-preferences has Cross-Collection IDOR in Access Control (Multi-Auth Environments)
UNKNOWN
CVE-2025-4644
Payload's SQLite adapter Session Fixation vulnerability
UNKNOWN
CVE-2025-4643
Payload does not invalidate JWTs after log out
CRITICAL 9.8
CVE-2022-27952
Unrestricted Upload of File with Dangerous Type in Payload
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes