Filament

Filamentphp · 14 CVEs

CVE-2026-104181
MEDIUM

Filament: Multi-factor authentication (app) management actions do not require password reauthentication

Oct 1, 2026

CVE-2026-84307
LOW

Filament: Password validity disclosure for accounts denied panel access on login page

Sep 1, 2026

CVE-2026-84306
MEDIUM

Filament: Multi-factor authentication (app) codes can still be used after a newer code has been used

Sep 1, 2026

CVE-2026-77567
HIGH

Filament: App-based MFA can be bypassed when recovery codes are enabled

Aug 24, 2026

CVE-2026-55409
HIGH

Filament: Disabled RichEditor field state can be used for XSS

Jun 22, 2026

CVE-2026-48067
MEDIUM

Filament: Inconsistent scope enforcement for AttachAction and AssociateAction Select fields

Jun 22, 2026

CVE-2026-48167
MEDIUM

Filament: Unvalidated ImageColumn and ImageEntry values can be used for XSS

Jun 22, 2026

CVE-2026-48500
MEDIUM

Filament: Unauthenticated temporary file upload on auth pages

Jun 22, 2026

CVE-2026-48166
MEDIUM

Filament: Timing-based user enumeration on login page

Jun 22, 2026

CVE-2026-48505
HIGH

Filament: Multi-factor authentication (app) recovery codes can still be used multiple times via concurrent submission

Jun 22, 2026

CVE-2026-33080
HIGH

Filament: Unvalidated Range and Values summarizer values can be used for XSS

Mar 20, 2026

CVE-2025-67507
HIGH

Filament's multi-factor authentication (app) recovery codes can be used multiple times

Dec 10, 2025

CVE-2024-51758
LOW

Exported files stored in default (`public`) filesystem if not reconfigured in filament

Nov 7, 2024

CVE-2024-47186
MEDIUM

Filament has unvalidated ColorColumn and ColorEntry values that can be used for Cross-site Scripting

Sep 27, 2024

Showing 1 to 14 of 14 CVEs