CVE-2026-90943

critical

Description

parallax filament-comments through 3.0.0 contains a stored cross-site scripting vulnerability in comment body rendering that allows authenticated panel users to inject malicious scripts. Attackers can store XSS payloads in comment bodies that execute in the browsers of other users viewing those comments, including administrators, enabling session token theft and unauthorized actions.

References

https://www.vulncheck.com/advisories/parallax-filament-comments-through-3.0.0-stored-xss-via-comment-body

https://packagist.org/packages/parallax/filament-comments

https://hackindex.io/research/stored-xss-filament-comments-unescaped-rendering

https://github.com/parallax/filament-comments/blob/3.0.0/src/Policies/FilamentCommentPolicy.php

https://github.com/parallax/filament-comments/blob/3.0.0/resources/views/comments.blade.php

Details

Source: Mitre, NVD

Published: 2026-09-14

Updated: 2026-09-24

Risk Information

CVSS v2

Base Score: 8.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:N

Severity: High

CVSS v3

Base Score: 8.7

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

Severity: High

CVSS v4

Base Score: 9.3

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N

Severity: Critical

EPSS

EPSS: 0.00236