Filemaker Server
Claris · 12 CVEs
An authorization bypass vulnerability in the FileMaker Server Web Publishing Engine allowed requests containing an exte…
Sep 23, 2026
An out-of-bounds read vulnerability in FileMaker Server for Linux allowed an attacker uploading a specially crafted ima…
Sep 23, 2026
A heap buffer overflow vulnerability in the FileMaker Server database engine block parsing routine allowed a maliciousl…
Sep 23, 2026
An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malici…
Jul 9, 2026
A cross-site scripting (XSS) vulnerability in a FileMaker WebDirect custom homepage could lead to unauthorized access a…
Feb 24, 2026
An authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privil…
Dec 16, 2025
Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications pas…
Dec 16, 2025
To enhance security, the FileMaker Server 22.0.4 installer now includes an option to disable IIS short filename enumera…
Dec 16, 2025
Claris International has resolved an issue of potentially allowing unauthorized access to records stored in databases h…
Apr 26, 2024
Claris International has successfully resolved an issue of potentially exposing password information to front-end websi…
Apr 26, 2024
Claris FileMaker Server before version 20.3.2 was susceptible to a reflected Cross-Site Scripting vulnerability due to…
Apr 15, 2024
A privilege escalation issue existed in FileMaker Server, potentially exposing sensitive information to front-end websi…
Mar 21, 2024
An XML External Entity issue in Claris FileMaker Pro and Server (including WebDirect) before 19.4.1 allows a remote att…
Nov 22, 2021
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-86934 | An authorization bypass vulnerability in the FileMaker Server Web Publishing Engine allowed requests containing an extended privilege header to bypass the disa… | CRITICAL | 0.33% | Sep 23, 2026 |
| CVE-2026-86930 | An out-of-bounds read vulnerability in FileMaker Server for Linux allowed an attacker uploading a specially crafted image file to a container field to disclose… | CRITICAL | 0.29% | Sep 23, 2026 |
| CVE-2026-86926 | A heap buffer overflow vulnerability in the FileMaker Server database engine block parsing routine allowed a maliciously crafted .fmp12 database file to cause… | HIGH | 0.13% | Sep 23, 2026 |
| CVE-2026-43752 | An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Source LLM set… | MEDIUM | 0.49% | Jul 9, 2026 |
| CVE-2025-46320 | A cross-site scripting (XSS) vulnerability in a FileMaker WebDirect custom homepage could lead to unauthorized access and remote code execution. This vulnerabi… | MEDIUM | 0.22% | Feb 24, 2026 |
| CVE-2025-46296 | An authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privileges to access administrative features s… | MEDIUM | 0.17% | Dec 16, 2025 |
| CVE-2025-46295 | Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrusted input into the text-substi… | CRITICAL | 1.04% | Dec 16, 2025 |
| CVE-2025-46294 | To enhance security, the FileMaker Server 22.0.4 installer now includes an option to disable IIS short filename enumeration by setting NtfsDisable8dot3NameCrea… | MEDIUM | 0.23% | Dec 16, 2025 |
| CVE-2024-27790 | Claris International has resolved an issue of potentially allowing unauthorized access to records stored in databases hosted on FileMaker Server. This issue ha… | HIGH | 0.46% | Apr 26, 2024 |
| CVE-2023-42955 | Claris International has successfully resolved an issue of potentially exposing password information to front-end websites when signed in to the Admin Console… | MEDIUM | 0.45% | Apr 26, 2024 |
| CVE-2024-27794 | Claris FileMaker Server before version 20.3.2 was susceptible to a reflected Cross-Site Scripting vulnerability due to an improperly handled parameter in the F… | MEDIUM | 0.31% | Apr 15, 2024 |
| CVE-2023-42954 | A privilege escalation issue existed in FileMaker Server, potentially exposing sensitive information to front-end websites when signed in to the Admin Console… | MEDIUM | 0.45% | Mar 21, 2024 |
| CVE-2021-44147 | An XML External Entity issue in Claris FileMaker Pro and Server (including WebDirect) before 19.4.1 allows a remote attacker to disclose local files via a craf… | MEDIUM | 1.17% | Nov 22, 2021 |
Showing 1 to 12 of 12 CVEs