Sploitus

CVE-2026-34750

No indexed exploits for CVE-2026-34750 yet

Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/storage-azure, @payloadcms/storage-gcs, @payloadcms/storage-r2, and @payloadcms/storage-s3, the client-upload signed-URL endpoints for S3, GCS, Azure, and R2 did not properly sanitize filenames. An attacker could craft filenames to escape the intended storage location. This issue has been patched in version 3.78.0 for @payloadcms/storage-azure, @payloadcms/storage-gcs, @payloadcms/storage-r2, and @payloadcms/storage-s3.

Payloadcms Payload
< 3.78.0
Fix
Available
CVSS 3.1
6.5 MEDIUM
EPSS
0.3% (27th percentile)
Weakness
CWE-22
NVD status
Analyzed
Published
2026-04-01
CVE-2026-34750 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-34750 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-34750 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.