Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Claris

First CVE: Feb 11, 2020Active for: 6 yearsTotal CVEs: 14
28.8
VTI Score
Low

Claris develops a narrow product line centered on FileMaker database and application-development platforms that serve business automation and data-management workloads, a niche but strategically important position in many organizations' infrastructure. The vendor's vulnerability profile clusters around web-facing and application-layer features, with recurring weaknesses including code injection, cross-site scripting, privilege-escalation flaws, and information-disclosure issues that reflect the attack surface of an embeddable database platform with web and API interfaces. Defenders should prioritize this vendor's advisories for any FileMaker deployments handling sensitive data; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Claris over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 11, 2020
6 years ago
Most Recent CVE
Jul 9, 2026
15 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-46295CRITICAL
Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrusted input into the text-substitution API. Because s
Dec 16, 20259.835NONO
CVE-2014-8347HIGH
An Authentication Bypass vulnerability exists in the MatchPasswordData function in DBEngine.dll in Filemaker Pro 13.03 and Filemaker Pro Advanced 12.04, which could let a malicious
Feb 11, 20207.829NOYES
CVE-2026-43685HIGH
A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to inject arbitrary operating system commands through unsanitized input
May 12, 20267.228NONO
CVE-2026-43680HIGH
A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to bypass a front-end restriction on OS Script schedule types and execu
May 12, 20267.227NONO
CVE-2026-43752MEDIUM
An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Source LLM setup feature in the Adm
Jul 9, 20264.925NONO
CVE-2023-42920HIGH
Claris International has fixed a dylib hijacking vulnerability in the FileMaker Pro.app and Claris Pro.app versions on macOS.
Mar 19, 20247.823NONO
CVE-2025-46320MEDIUM
A cross-site scripting (XSS) vulnerability in a FileMaker WebDirect custom homepage could lead to unauthorized access and remote code execution. This vulnerability has been fully a
Feb 24, 20266.122NONO
CVE-2024-27790HIGH
Claris International has resolved an issue of potentially allowing unauthorized access to records stored in databases hosted on FileMaker Server. This issue has been fixed in FileM
May 14, 20247.522NONO
CVE-2025-46296MEDIUM
An authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privileges to access administrative features such as viewing licens
Dec 16, 20255.421NONO
CVE-2025-46294MEDIUM
To enhance security, the FileMaker Server 22.0.4 installer now includes an option to disable IIS short filename enumeration by setting NtfsDisable8dot3NameCreation in the Windows r
Dec 16, 20255.320NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
57%
36%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (21.4%)
Network11 (78.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (78.6%)
Unknown0 (0.0%)
Required3 (21.4%)
Privileges Required
Low3 (21.4%)
High5 (35.7%)
None6 (42.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
7.1% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Claris.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Claris — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Claris's Products

View all 2 CNAs →

Top CWEs