Filamentphp
Filamentphp Filament: vulnerabilities and CVEs
Filamentphp Filament has 13 published vulnerabilities, 11 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs13
Last 12 months11
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-104181 | Medium (5.4) | 0.34% | — | Oct 1, 2026 | Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.13.3 and 5.8.3, app-based multi-factor authentication management actions do not consistently require confirmation… |
| CVE-2026-84307 | Low (3.7) | 0.46% | — | Sep 1, 2026 | Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.12.5 and 5.7.5, packages/panels/src/Auth/Pages/Login.php presents the multi-factor authentication challenge… |
| CVE-2026-84306 | Medium (6.5) | 0.45% | — | Sep 1, 2026 | Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.12.6 and 5.7.6, packages/panels/src/Auth/MultiFactor/App/AppAuthentication.php uses… |
| CVE-2026-77567 | High (8.1) | 0.55% | — | Aug 24, 2026 | Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.0, incorrect challenge-form required-field handling allows app-based multi-factor authentication to… |
| CVE-2026-55409 | High (7.6) | 0.28% | — | Jun 22, 2026 | Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.53, a disabled RichEditor field rendered its raw state without sanitizing HTML. Where the data stored in this… |
| CVE-2026-48505 | High (7.4) | 0.30% | — | Jun 22, 2026 | Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, a flaw in the handling of recovery codes for app-based multi-factor authentication allows the… |
| CVE-2026-48500 | Medium (6.5) | 0.34% | — | Jun 22, 2026 | Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.52, 4.11.5, and 5.6.5, any schema can contain a file upload form field, so Filament applies Livewire's… |
| CVE-2026-48167 | Medium (6.4) | 0.25% | — | Jun 22, 2026 | Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, the ImageColumn and ImageEntry components render raw database values without escaping HTML. Where… |
| CVE-2026-48166 | Medium (5.3) | 0.34% | — | Jun 22, 2026 | Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, the login page has an observable timing discrepancy that allows unauthenticated attackers to… |
| CVE-2026-33080 | Medium (5.4) | 0.36% | — | Mar 20, 2026 | Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.8.4 and 5.0.0 through 5.3.4 have two Filament Table summarizers (Range, Values) that render raw database… |
| CVE-2025-67507 | High (8.1) | 0.34% | — | Dec 10, 2025 | Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.3.0 contain a flaw in the handling of recovery codes for app-based multi-factor authentication, allowing… |
| CVE-2024-51758 | Low (2.3) | 0.56% | — | Nov 7, 2024 | Filament is a collection of full-stack components for accelerated Laravel development. All Filament features that interact with storage use the `default_filesystem_disk` config option. This allows the user to easily… |
| CVE-2024-47186 | Medium (6.1) | 0.42% | — | Sep 27, 2024 | Filament is a collection of full-stack components for Laravel development. Versions of Filament from v3.0.0 through v3.2.114 are affected by a cross-site scripting (XSS) vulnerability. If values passed to a… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.