PatchSiren

filamentphp CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM filamentphp CVE published 2026-09-01

CVE-2026-84306

CVE-2026-84306 is a medium-severity vulnerability in Laravel Filament's multi-factor authentication system. An attacker who obtains the target account's password and one app-based MFA code can reuse that code for approximately four minutes, even after the legitimate account holder logs in with a newer code. This issue affects Filament versions from 4.0.0 to 4.12.5 and 5.0.0 to 5.7.5. The vulnerability is [truncated]

HIGH filamentphp CVE published 2026-08-24

CVE-2026-77567

CVE-2026-77567 is a high-severity vulnerability in Filament, a collection of full-stack components for accelerated Laravel development. The issue allows app-based multi-factor authentication to be bypassed when recovery codes are enabled, but email-based multi-factor authentication is not affected. This vulnerability was fixed in versions 4.12.0 and 5.7.0.

MEDIUM filamentphp CVE published 2026-06-22

CVE-2026-48500

CVE-2026-48500 is a medium-severity vulnerability in Filament, a collection of full-stack components for accelerated Laravel development. The vulnerability allows unauthenticated attackers to upload arbitrary files to the application's temporary storage, potentially exhausting disk space or inflating storage costs. This issue affects Filament versions from 3.0.0 until 3.3.52, 4.11.5, and 5.6.5. The vulner [truncated]

MEDIUM filamentphp CVE published 2026-06-22

CVE-2026-48167

CVE-2026-48167 is a stored cross-site scripting (XSS) vulnerability affecting Filament's ImageColumn and ImageEntry components. The vulnerability exists in versions 4.0.0 through 4.11.5 and 5.6.5, where these components render raw database values without proper HTML escaping. If the data passed to these components is not validated, an attacker could inject malicious HTML or JavaScript. This stored XSS vul [truncated]

MEDIUM filamentphp CVE published 2026-06-22

CVE-2026-48166

A vulnerability in Filament, a collection of full-stack components for accelerated Laravel development, has been discovered. The issue, tracked as CVE-2026-48166, affects versions 4.0.0 through 4.11.5 and 5.6.5. It allows unauthenticated attackers to enumerate registered email addresses by exploiting an observable timing discrepancy on the login page. The impact of this vulnerability is limited to disclos [truncated]

MEDIUM filamentphp CVE published 2026-06-22

CVE-2026-48067

CVE-2026-48067 is a vulnerability in Filament, a collection of full-stack components for accelerated Laravel development. The vulnerability affects filament/actions versions 4.0.0 to 4.11.4 and 5.6.4, and filament/tables versions 3.0.0 to 3.3.51. An attacker who can trigger the AttachAction and AssociateAction could tamper with the Livewire component's state and submit an out-of-scope value due to a discr [truncated]