{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/parallax/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:parallax:filament-comments:*:*:*:*:*:*:*:*"],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["filament-comments (\u003c= 3.0.0)"],"_cs_severities":["high"],"_cs_tags":["xss","web-vulnerability","php"],"_cs_type":"advisory","_cs_vendors":["parallax"],"content_html":"\u003cp\u003eCVE-2026-90943 identifies a stored cross-site scripting (XSS) vulnerability within the parallax filament-comments package for the Filament PHP framework, affecting all versions up to and including 3.0.0. The vulnerability resides in the comment body rendering component, which fails to properly sanitize user-supplied input before displaying it in the administrative panel or public-facing views. An authenticated user can inject malicious JavaScript into a comment body. When a victim, such as an administrator with higher privileges, views the rendered comment, the malicious payload executes in their browser session. This flaw poses a significant risk to the integrity of the administrative session, potentially allowing for session token theft, unauthorized data access, or the performance of administrative actions on behalf of the victim. Defenders should prioritize updating to a patched version or implementing strict content security policies to mitigate script execution.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the execution of arbitrary JavaScript within the security context of a logged-in user. In an administrative panel, this facilitates account takeover via session hijacking or the unauthorized modification of system settings, impacting the confidentiality and integrity of the affected application.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the parallax filament-comments package to the latest version that includes sanitization patches for comment body rendering.\u003c/li\u003e\n\u003cli\u003eImplement a Content Security Policy (CSP) that restricts script sources and prevents the execution of inline scripts to mitigate the impact of potential XSS vulnerabilities.\u003c/li\u003e\n\u003cli\u003eReview administrative access logs for unusual activity associated with user accounts that have recently posted comments.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-14T17:34:46Z","date_published":"2026-09-14T17:34:46Z","id":"https://feed.craftedsignal.io/briefs/2026-09-filament-comments-xss/","summary":"CVE-2026-90943 is a stored cross-site scripting vulnerability in filament-comments \u003c= 3.0.0, allowing authenticated users to inject malicious scripts into comment bodies for execution in the browsers of other users.","title":"Stored XSS in parallax filament-comments","url":"https://feed.craftedsignal.io/briefs/2026-09-filament-comments-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Parallax","version":"https://jsonfeed.org/version/1.1"}