Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-55409

Опубликовано: 22 июн. 2026
Источник: nvd
CVSS3: 7.6
EPSS Низкий

Описание

Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.53, a disabled RichEditor field rendered its raw state without sanitizing HTML. Where the data stored in this field's state isn't sanitized already when the form state was filled, an attacker could plant malicious HTML or JavaScript and achieve XSS that executes for users who view the form. This vulnerability is fixed in 3.3.53.

EPSS

Процентиль: 21%
0.00284
Низкий

7.6 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 7.6
github
3 месяца назад

Filament: Disabled RichEditor field state can be used for XSS

EPSS

Процентиль: 21%
0.00284
Низкий

7.6 High

CVSS3

Дефекты

CWE-79