CVE-2026-48167Medium· 6.4▾ SunlitFilament: Unvalidated ImageColumn and ImageEntry values can be used for XSS
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.1%
0.1% → 0.2%
The ImageColumn and ImageEntry components render raw database values without escaping HTML. Where the data passed to these components isn't validated, an attacker could plant malicious HTML or JavaScript and achieve stored XSS that executes for users who view the table or schema.
filament/infolists >= 4.0.0, <= 4.11.4filament/tables >= 4.0.0, <= 4.11.4filament/infolists >= 5.0.0, <= 5.6.4filament/tables >= 5.0.0, <= 5.6.4Upgrade to a patched release:
filament/infolists 4.11.5filament/tables 4.11.5filament/infolists 5.6.5filament/tables 5.6.5Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55409High· 7.6Filament: Disabled RichEditor field state can be used for XSS
CVE-2026-77567High· 8.1Filament is a collection of full-stack components for accelerated Laravel development
CVE-2026-84307Low· 3.7Filament is a collection of full-stack components for accelerated Laravel development
CVE-2026-84306Medium· 6.5Filament is a collection of full-stack components for accelerated Laravel development
CVE-2021-41164High· 8.2CKEditor4 is an open source WYSIWYG HTML editor
CVE-2021-41184Medium· 6.5jQuery-UI is the official jQuery user interface library