High severityNVD Advisory· Published Mar 20, 2026· Updated Mar 25, 2026
Filament: Unvalidated Range and Values summarizer values can be used for XSS
CVE-2026-33080
Description
Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.8.4 and 5.0.0 through 5.3.4 have two Filament Table summarizers (Range, Values) that render raw database values without escaping HTML. If there is a lack of validation for the data in the columns that use these summarizers, an attacker could plant malicious HTML / JavaScript and achieve stored XSS that executes for users who view the table with those summarizers. This issue has been patched in versions 4.8.5 and 5.3.5.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
filament/tablesPackagist | >= 4.0.0, < 4.8.5 | 4.8.5 |
filament/tablesPackagist | >= 5.0.0, < 5.3.5 | 5.3.5 |
Affected products
2- Range: >= 4.0.0, < 4.8.5
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-vv3x-j2x5-36jcghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-33080ghsaADVISORY
- github.com/filamentphp/filament/commit/efa041aeeb4b1a99acd48aaa05584993c926d1edghsax_refsource_MISCWEB
- github.com/filamentphp/filament/releases/tag/v4.8.5ghsax_refsource_MISCWEB
- github.com/filamentphp/filament/releases/tag/v5.3.5ghsax_refsource_MISCWEB
- github.com/filamentphp/filament/security/advisories/GHSA-vv3x-j2x5-36jcghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.