@payloadcms/next has Stored XSS in Admin Panel
A stored Cross-site Scripting (XSS) vulnerability existed in the admin panel. An authenticated user with write access to a collection could save content that, when viewed by another user, would execute in their browser. Consumers are affected if ALL of these are true: Payload version < v3.78.0 At least one collection with versions enabled An authenticated user has create or update access to that collection