Filament
Filamentphp · 14 CVEs
Filament: Multi-factor authentication (app) management actions do not require password reauthentication
Oct 1, 2026
Filament: Password validity disclosure for accounts denied panel access on login page
Sep 1, 2026
Filament: Multi-factor authentication (app) codes can still be used after a newer code has been used
Sep 1, 2026
Filament: App-based MFA can be bypassed when recovery codes are enabled
Aug 24, 2026
Filament: Disabled RichEditor field state can be used for XSS
Jun 22, 2026
Filament: Inconsistent scope enforcement for AttachAction and AssociateAction Select fields
Jun 22, 2026
Filament: Unvalidated ImageColumn and ImageEntry values can be used for XSS
Jun 22, 2026
Filament: Unauthenticated temporary file upload on auth pages
Jun 22, 2026
Filament: Timing-based user enumeration on login page
Jun 22, 2026
Filament: Multi-factor authentication (app) recovery codes can still be used multiple times via concurrent submission
Jun 22, 2026
Filament: Unvalidated Range and Values summarizer values can be used for XSS
Mar 20, 2026
Filament's multi-factor authentication (app) recovery codes can be used multiple times
Dec 10, 2025
Exported files stored in default (`public`) filesystem if not reconfigured in filament
Nov 7, 2024
Filament has unvalidated ColorColumn and ColorEntry values that can be used for Cross-site Scripting
Sep 27, 2024
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-104181 | Filament: Multi-factor authentication (app) management actions do not require password reauthentication | MEDIUM | 0.34% | Oct 1, 2026 |
| CVE-2026-84307 | Filament: Password validity disclosure for accounts denied panel access on login page | LOW | 0.46% | Sep 1, 2026 |
| CVE-2026-84306 | Filament: Multi-factor authentication (app) codes can still be used after a newer code has been used | MEDIUM | 0.45% | Sep 1, 2026 |
| CVE-2026-77567 | Filament: App-based MFA can be bypassed when recovery codes are enabled | HIGH | 0.55% | Aug 24, 2026 |
| CVE-2026-55409 | Filament: Disabled RichEditor field state can be used for XSS | HIGH | 0.28% | Jun 22, 2026 |
| CVE-2026-48067 | Filament: Inconsistent scope enforcement for AttachAction and AssociateAction Select fields | MEDIUM | 0.30% | Jun 22, 2026 |
| CVE-2026-48167 | Filament: Unvalidated ImageColumn and ImageEntry values can be used for XSS | MEDIUM | 0.25% | Jun 22, 2026 |
| CVE-2026-48500 | Filament: Unauthenticated temporary file upload on auth pages | MEDIUM | 0.34% | Jun 22, 2026 |
| CVE-2026-48166 | Filament: Timing-based user enumeration on login page | MEDIUM | 0.34% | Jun 22, 2026 |
| CVE-2026-48505 | Filament: Multi-factor authentication (app) recovery codes can still be used multiple times via concurrent submission | HIGH | 0.30% | Jun 22, 2026 |
| CVE-2026-33080 | Filament: Unvalidated Range and Values summarizer values can be used for XSS | HIGH | 0.36% | Mar 20, 2026 |
| CVE-2025-67507 | Filament's multi-factor authentication (app) recovery codes can be used multiple times | HIGH | 0.34% | Dec 10, 2025 |
| CVE-2024-51758 | Exported files stored in default (`public`) filesystem if not reconfigured in filament | LOW | 0.56% | Nov 7, 2024 |
| CVE-2024-47186 | Filament has unvalidated ColorColumn and ColorEntry values that can be used for Cross-site Scripting | MEDIUM | 0.42% | Sep 27, 2024 |
Showing 1 to 14 of 14 CVEs