Home/Product/claris filemaker server
Product

claris filemaker server

10 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-46320
< 21.1.7
A cross-site scripting (XSS) vulnerability in a FileMaker WebDirect custom homepage could lead to unauthorized access and remote c
6.1MEDIUM
CVE-2025-46296
< 22.0.4
An authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privileges to acc
5.4MEDIUM
CVE-2025-46295
< 22.0.4
Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrust
9.8CRITICAL
CVE-2025-46294
< 22.0.4
To enhance security, the FileMaker Server 22.0.4 installer now includes an option to disable IIS short filename enumeration by set
5.3MEDIUM
CVE-2024-27790
< 20.3.2
Claris International has resolved an issue of potentially allowing unauthorized access to records stored in databases hosted on Fi
7.5HIGH
CVE-2023-42955
< 20.3.1
Claris International has successfully resolved an issue of potentially exposing password information to front-end websites when si
4.9MEDIUM
CVE-2024-27794
< 20.3.2
Claris FileMaker Server before version 20.3.2 was susceptible to a reflected Cross-Site Scripting vulnerability due to an improper
6.1MEDIUM
CVE-2023-42954
< 20.3.1
A privilege escalation issue existed in FileMaker Server, potentially exposing sensitive information to front-end websites when si
4.9MEDIUM
CVE-2021-44147
< 19.4.1
An XML External Entity issue in Claris FileMaker Pro and Server (including WebDirect) before 19.4.1 allows a remote attacker to di
5.5MEDIUM
CVE-2007-6104
all versions
Cross-site scripting (XSS) vulnerability in the Instant Web Publishing feature in FileMaker Pro 7 and 8, Server 7 and 8, and Devel
threatengine.sh