cbcvebase.
CVE-2025-4643
published 2025-08-29

CVE-2025-4643: Payload uses JSON Web Tokens (JWT) for authentication. After log out JWT is not invalidated, which allows an attacker who has stolen or intercepted token to…

PriorityP336medium6.3CVSS 4.0
AVNACHATNPRNUINVCLVILVANSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.40%
32.9th percentile
Payload uses JSON Web Tokens (JWT) for authentication. After log out JWT is not invalidated, which allows an attacker who has stolen or intercepted token to freely reuse it until expiration date (which is by default set to 2 hours, but can be changed). This issue has been fixed in version 3.44.0 of Payload.

Affected

4 ranges
VendorProductVersion rangeFixed in
payload_cmspayload< 3.44.03.44.0
payloadcmsgraphql>= 0 < 3.44.03.44.0
payloadcmsnext>= 0 < 3.44.03.44.0
payloadcmspayload>= 0 < 3.44.03.44.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.