CVE-2026-55409High· 7.6▾ TwilightFilament: Disabled RichEditor field state can be used for XSS
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.2%
0.2% → 0.3%
In Filament v3, a disabled RichEditor field rendered its raw state without sanitizing HTML. Where the data stored in this field's state isn't sanitized already when the form state was filled, an attacker could plant malicious HTML or JavaScript and achieve XSS that executes for users who view the form.
Please note that Filament v4 and above does not use the same mechanism for rendering a disabled RichEditor so this advisory does not apply.
filament/forms >= 3.0.0, <= 3.3.52Upgrade to a patched release:
filament/forms 3.3.53Connected by shared product, vendor, weakness, or advisory.
CVE-2026-48167Medium· 6.4Filament: Unvalidated ImageColumn and ImageEntry values can be used for XSS
CVE-2026-77567High· 8.1Filament is a collection of full-stack components for accelerated Laravel development
CVE-2026-84307Low· 3.7Filament is a collection of full-stack components for accelerated Laravel development
CVE-2026-84306Medium· 6.5Filament is a collection of full-stack components for accelerated Laravel development
CVE-2021-41164High· 8.2CKEditor4 is an open source WYSIWYG HTML editor
CVE-2021-41184Medium· 6.5jQuery-UI is the official jQuery user interface library