๐Ÿ” CVE Alert

CVE-2026-90943

HIGH 8.7

parallax filament-comments through 3.0.0 Stored XSS via Comment Body

CVSS Score
8.7
EPSS Score
0.0%
EPSS Percentile
0th

parallax filament-comments through 3.0.0 contains a stored cross-site scripting vulnerability in comment body rendering that allows authenticated panel users to inject malicious scripts. Attackers can store XSS payloads in comment bodies that execute in the browsers of other users viewing those comments, including administrators, enabling session token theft and unauthorized actions.

CWE CWE-79
Vendor parallax
Product filament-comments
Published Sep 14, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for parallax filament-comments

Be the first to know when new high vulnerabilities affecting parallax filament-comments are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

parallax / filament-comments
0 โ‰ค 3.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
hackindex.io: https://hackindex.io/research/stored-xss-filament-comments-unescaped-rendering github.com: https://github.com/parallax/filament-comments/blob/3.0.0/resources/views/comments.blade.php github.com: https://github.com/parallax/filament-comments/blob/3.0.0/src/Policies/FilamentCommentPolicy.php packagist.org: https://packagist.org/packages/parallax/filament-comments vulncheck.com: https://www.vulncheck.com/advisories/parallax-filament-comments-through-3.0.0-stored-xss-via-comment-body

Credits

Joshua van der Poll