Claris develops a narrow product line centered on FileMaker database and application-development platforms that serve business automation and data-management workloads, a niche but strategically important position in many organizations' infrastructure. The vendor's vulnerability profile clusters around web-facing and application-layer features, with recurring weaknesses including code injection, cross-site scripting, privilege-escalation flaws, and information-disclosure issues that reflect the attack surface of an embeddable database platform with web and API interfaces. Defenders should prioritize this vendor's advisories for any FileMaker deployments handling sensitive data; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Claris over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-46295CRITICAL Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrusted input into the text-substitution API. Because s | Dec 16, 2025 | 9.8 | 35 | NO | NO |
CVE-2014-8347HIGH An Authentication Bypass vulnerability exists in the MatchPasswordData function in DBEngine.dll in Filemaker Pro 13.03 and Filemaker Pro Advanced 12.04, which could let a malicious | Feb 11, 2020 | 7.8 | 29 | NO | YES |
CVE-2026-43685HIGH A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to inject arbitrary operating system commands through unsanitized input | May 12, 2026 | 7.2 | 28 | NO | NO |
CVE-2026-43680HIGH A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to bypass a front-end restriction on OS Script schedule types and execu | May 12, 2026 | 7.2 | 27 | NO | NO |
CVE-2026-43752MEDIUM An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Source LLM setup feature in the Adm | Jul 9, 2026 | 4.9 | 25 | NO | NO |
CVE-2023-42920HIGH Claris International has fixed a dylib hijacking vulnerability in the FileMaker Pro.app and Claris Pro.app versions on macOS. | Mar 19, 2024 | 7.8 | 23 | NO | NO |
CVE-2025-46320MEDIUM A cross-site scripting (XSS) vulnerability in a FileMaker WebDirect custom homepage could lead to unauthorized access and remote code execution. This vulnerability has been fully a | Feb 24, 2026 | 6.1 | 22 | NO | NO |
CVE-2024-27790HIGH Claris International has resolved an issue of potentially allowing unauthorized access to records stored in databases hosted on FileMaker Server. This issue has been fixed in FileM | May 14, 2024 | 7.5 | 22 | NO | NO |
CVE-2025-46296MEDIUM An authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privileges to access administrative features such as viewing licens | Dec 16, 2025 | 5.4 | 21 | NO | NO |
CVE-2025-46294MEDIUM To enhance security, the FileMaker Server 22.0.4 installer now includes an option to disable IIS short filename enumeration by setting NtfsDisable8dot3NameCreation in the Windows r | Dec 16, 2025 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Claris.
Media articles that mention a CVE ID that affects a product developed by Claris — matched by CVE ID, not by vendor name.