CRITICAL 9.3 NVD
CVE-2026-90943
parallax filament-comments through 3.0.0 contains a stored cross-site scripting vulnerability in comment body rendering that allows authenticated panel users to
parallax filament-comments through 3.0.0 contains a stored cross-site scripting vulnerability in comment body rendering that allows authenticated panel users to inject malicious scripts. Attackers can store XSS payloads in comment bodies that execute in the browsers of other users viewing those comments, including administrators, enabling session token theft and unauthorized actions.
References
- https://github.com/parallax/filament-comments/blob/3.0.0/resources/views/comments.blade.ph
- https://github.com/parallax/filament-comments/blob/3.0.0/src/Policies/FilamentCommentPolic
- https://hackindex.io/research/stored-xss-filament-comments-unescaped-rendering
- https://packagist.org/packages/parallax/filament-comments
- https://www.vulncheck.com/advisories/parallax-filament-comments-through-3.0.0-stored-xss-v
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-09-14 via NVD.
Risk Timeline
CVE Disclosed2026-09-14 · 0 days ago
Remediation Resources
Analysis & PoC
packagist.org/packages/parallax/filament-comments
vulnfeed aggregates 10822 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.