Vendor
CVE-2026-90943 is a stored cross-site scripting vulnerability in filament-comments <= 3.0.0, allowing authenticated users to inject malicious scripts into comment bodies for execution in the browsers of other users.