Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 14 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 14 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | parallax filament-comments through 3.0.0 contains a stored cross-site scripting vulnerability in comment body rendering that allows authenticated panel users to inject malicious scripts. Attackers can store XSS payloads in comment bodies that execute in the browsers of other users viewing those comments, including administrators, enabling session token theft and unauthorized actions. | |
| Title | parallax filament-comments through 3.0.0 Stored XSS via Comment Body | |
| Weaknesses | CWE-79 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-14T20:07:01.726Z
Reserved: 2026-09-14T11:34:24.687Z
Link: CVE-2026-90943
Updated: 2026-09-14T19:21:29.018Z
Status : Received
Published: 2026-09-14T16:17:41.693
Modified: 2026-09-14T20:17:03.320
Link: CVE-2026-90943
No data.
OpenCVE Enrichment
No data.