Filemaker Server

Claris · 12 CVEs

CVE-2026-86934
CRITICAL

An authorization bypass vulnerability in the FileMaker Server Web Publishing Engine allowed requests containing an exte…

Sep 23, 2026

CVE-2026-86930
CRITICAL

An out-of-bounds read vulnerability in FileMaker Server for Linux allowed an attacker uploading a specially crafted ima…

Sep 23, 2026

CVE-2026-86926
HIGH

A heap buffer overflow vulnerability in the FileMaker Server database engine block parsing routine allowed a maliciousl…

Sep 23, 2026

CVE-2026-43752
MEDIUM

An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malici…

Jul 9, 2026

CVE-2025-46320
MEDIUM

A cross-site scripting (XSS) vulnerability in a FileMaker WebDirect custom homepage could lead to unauthorized access a…

Feb 24, 2026

CVE-2025-46296
MEDIUM

An authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privil…

Dec 16, 2025

CVE-2025-46295
CRITICAL

Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications pas…

Dec 16, 2025

CVE-2025-46294
MEDIUM

To enhance security, the FileMaker Server 22.0.4 installer now includes an option to disable IIS short filename enumera…

Dec 16, 2025

CVE-2024-27790
HIGH

Claris International has resolved an issue of potentially allowing unauthorized access to records stored in databases h…

Apr 26, 2024

CVE-2023-42955
MEDIUM

Claris International has successfully resolved an issue of potentially exposing password information to front-end websi…

Apr 26, 2024

CVE-2024-27794
MEDIUM

Claris FileMaker Server before version 20.3.2 was susceptible to a reflected Cross-Site Scripting vulnerability due to…

Apr 15, 2024

CVE-2023-42954
MEDIUM

A privilege escalation issue existed in FileMaker Server, potentially exposing sensitive information to front-end websi…

Mar 21, 2024

CVE-2021-44147
MEDIUM

An XML External Entity issue in Claris FileMaker Pro and Server (including WebDirect) before 19.4.1 allows a remote att…

Nov 22, 2021

Showing 1 to 12 of 12 CVEs