Filament Stored Cross-Site Scripting Vulnerability in Table Summarizers

Vulnerability

A stored cross-site scripting vulnerability has been identified in Filament versions 4.0.0 prior to 4.8.5 and 5.0.0 prior to 5.3.5. The issue arises in two Filament Table summarizers, 'Range' and 'Values', which display raw database values without proper HTML escaping. If the data in the relevant columns is not validated, an attacker could inject malicious HTML or JavaScript, leading to stored cross-site scripting that executes for users viewing the table with those summarizers.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the affected table.

Remediation

Users can upgrade to Filament versions 4.8.5 or 5.3.5 to address this vulnerability.

Added: Mar 20, 2026, 9:24 AM
Updated: Mar 20, 2026, 9:24 AM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
1.7
exploitability
5.4
remediation
7.7
relevance
4.2
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.