« Back to list

Filamentphp

Filamentphp Filament: vulnerabilities and CVEs

Filamentphp Filament has 13 published vulnerabilities, 11 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs13
Last 12 months11
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-104181Medium (5.4)0.34%—Oct 1, 2026
Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.13.3 and 5.8.3, app-based multi-factor authentication management actions do not consistently require confirmation…
CVE-2026-84307Low (3.7)0.46%—Sep 1, 2026
Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.12.5 and 5.7.5, packages/panels/src/Auth/Pages/Login.php presents the multi-factor authentication challenge…
CVE-2026-84306Medium (6.5)0.45%—Sep 1, 2026
Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.12.6 and 5.7.6, packages/panels/src/Auth/MultiFactor/App/AppAuthentication.php uses…
CVE-2026-77567High (8.1)0.55%—Aug 24, 2026
Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.0, incorrect challenge-form required-field handling allows app-based multi-factor authentication to…
CVE-2026-55409High (7.6)0.28%—Jun 22, 2026
Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.53, a disabled RichEditor field rendered its raw state without sanitizing HTML. Where the data stored in this…
CVE-2026-48505High (7.4)0.30%—Jun 22, 2026
Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, a flaw in the handling of recovery codes for app-based multi-factor authentication allows the…
CVE-2026-48500Medium (6.5)0.34%—Jun 22, 2026
Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.52, 4.11.5, and 5.6.5, any schema can contain a file upload form field, so Filament applies Livewire's…
CVE-2026-48167Medium (6.4)0.25%—Jun 22, 2026
Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, the ImageColumn and ImageEntry components render raw database values without escaping HTML. Where…
CVE-2026-48166Medium (5.3)0.34%—Jun 22, 2026
Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, the login page has an observable timing discrepancy that allows unauthenticated attackers to…
CVE-2026-33080Medium (5.4)0.36%—Mar 20, 2026
Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.8.4 and 5.0.0 through 5.3.4 have two Filament Table summarizers (Range, Values) that render raw database…
CVE-2025-67507High (8.1)0.34%—Dec 10, 2025
Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.3.0 contain a flaw in the handling of recovery codes for app-based multi-factor authentication, allowing…
CVE-2024-51758Low (2.3)0.56%—Nov 7, 2024
Filament is a collection of full-stack components for accelerated Laravel development. All Filament features that interact with storage use the `default_filesystem_disk` config option. This allows the user to easily…
CVE-2024-47186Medium (6.1)0.42%—Sep 27, 2024
Filament is a collection of full-stack components for Laravel development. Versions of Filament from v3.0.0 through v3.2.114 are affected by a cross-site scripting (XSS) vulnerability. If values passed to a…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1078 Valid Accounts3
  2. T1190 Exploit Public-Facing Application2
  3. T1210 Exploitation of Remote Services2
  4. T1059.007 JavaScript1
  5. T1078.001 Default Accounts1
  6. T1189 Drive-by Compromise1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.