Filters apply as you choose them.
element-plus 2.0.5 is vulnerable to Cross Site Scripting (XSS) via el-table-column.