CVE-2026-55409
- EPSS 0.17%
- Veröffentlicht 22.06.2026 21:47:51
- Zuletzt bearbeitet 23.06.2026 15:03:56
Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.53, a disabled RichEditor field rendered its raw state without sanitizing HTML. Where the data stored in this field's state isn't sanitized al...
CVE-2026-48067
- EPSS 0.18%
- Veröffentlicht 22.06.2026 21:46:27
- Zuletzt bearbeitet 23.06.2026 15:16:34
Filament is a collection of full-stack components for accelerated Laravel development. From filament/actions 4.0.0 until 4.11.4 and 5.6.4 and from filament/tables 3.0.0 until 3.3.51, the recordSelectOptionsQuery() method may be used to scope the opti...
CVE-2026-48167
- EPSS 0.15%
- Veröffentlicht 22.06.2026 21:43:42
- Zuletzt bearbeitet 23.06.2026 15:03:56
Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, the ImageColumn and ImageEntry components render raw database values without escaping HTML. Where the data passed to these compo...
CVE-2026-48500
- EPSS 0.21%
- Veröffentlicht 22.06.2026 21:41:17
- Zuletzt bearbeitet 23.06.2026 15:16:34
Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.52, 4.11.5, and 5.6.5, any schema can contain a file upload form field, so Filament applies Livewire's WithFileUploads trait to the Livewire c...
CVE-2026-48166
- EPSS 0.21%
- Veröffentlicht 22.06.2026 21:40:01
- Zuletzt bearbeitet 23.06.2026 15:03:56
Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, the login page has an observable timing discrepancy that allows unauthenticated attackers to enumerate registered email addresse...
CVE-2026-48505
- EPSS 0.19%
- Veröffentlicht 22.06.2026 21:39:26
- Zuletzt bearbeitet 23.06.2026 15:16:35
Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, a flaw in the handling of recovery codes for app-based multi-factor authentication allows the same recovery code to be reused vi...
CVE-2026-33080
- EPSS 0.3%
- Veröffentlicht 20.03.2026 08:58:45
- Zuletzt bearbeitet 23.03.2026 15:43:48
Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.8.4 and 5.0.0 through 5.3.4 have two Filament Table summarizers (Range, Values) that render raw database values without escaping HTML. If ...
CVE-2025-67507
- EPSS 0.31%
- Veröffentlicht 10.12.2025 00:43:06
- Zuletzt bearbeitet 04.03.2026 20:42:39
Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.3.0 contain a flaw in the handling of recovery codes for app-based multi-factor authentication, allowing the same recovery code to be reus...
CVE-2024-51758
- EPSS 0.54%
- Veröffentlicht 07.11.2024 18:15:17
- Zuletzt bearbeitet 15.04.2026 00:35:42
Filament is a collection of full-stack components for accelerated Laravel development. All Filament features that interact with storage use the `default_filesystem_disk` config option. This allows the user to easily swap their storage driver to somet...
CVE-2024-47186
- EPSS 0.38%
- Veröffentlicht 27.09.2024 21:15:03
- Zuletzt bearbeitet 07.10.2024 13:30:55
Filament is a collection of full-stack components for Laravel development. Versions of Filament from v3.0.0 through v3.2.114 are affected by a cross-site scripting (XSS) vulnerability. If values passed to a `ColorColumn` or `ColumnEntry` are not vali...