VYPR
Medium severity6.4NVD Advisory· Published Jun 22, 2026· Updated Jun 23, 2026

CVE-2026-48167

CVE-2026-48167

Description

Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, the ImageColumn and ImageEntry components render raw database values without escaping HTML. Where the data passed to these components isn't validated, an attacker could plant malicious HTML or JavaScript and achieve stored XSS that executes for users who view the table or schema. This vulnerability is fixed in 4.11.5 and 5.6.5.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
filament/infolistsPackagist
>= 4.0.0, < 4.11.54.11.5
filament/tablesPackagist
>= 4.0.0, < 4.11.54.11.5
filament/infolistsPackagist
>= 5.0.0, < 5.6.55.6.5
filament/tablesPackagist
>= 5.0.0, < 5.6.55.6.5

Affected products

1

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.