Impact
parallax filament-comments through version 3.0.0 contains a stored cross‑site scripting vulnerability in the comment body rendering routine. When an authenticated panel user posts a comment containing malicious JavaScript, the content is stored and later rendered unescaped. Any user—including administrators—who views the comment will have the script executed in their browser, allowing an attacker to steal session cookies, carry out credential‑stealing or perform other unauthorized actions.
Affected Systems
The vulnerability affects the Parallax filament-comments package up to and including version 3.0.0. All installations using any version of filament-comments that has not been upgraded beyond 3.0.0 are susceptible. The package is a Laravel component used within the Filament admin panel.
Risk and Exploitability
The flaw scores a CVSS of 9.3, indicating critical severity. The EPSS score is not available, so the exploit probability cannot be quantified, but the high CVSS suggests that attackers would prioritize this issue. Because the vulnerability requires an authenticated panel user, the attack surface is limited to users with comment‑posting privileges; however, once an attacker holds such a credential, the stored XSS can be abused on any number of users. The vulnerability is not currently listed in the CISA KEV catalog.
OpenCVE Enrichment