<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – FileMaker Platform (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/filemaker.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/filemaker-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – FileMaker Platform (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:48 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-43685 – A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43685</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43685</guid>
    <pubDate>Tue, 12 May 2026 23:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43685</strong></p>
  <p>A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to inject arbitrary operating system commands through unsanitized input in the External ODBC Data Source connection test feature. This issue is fixed in FileMaker Cloud 2.22.0.5.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43685">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43680 – A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43680</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43680</guid>
    <pubDate>Tue, 12 May 2026 23:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43680</strong></p>
  <p>A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to bypass a front-end restriction on OS Script schedule types and execute arbitrary operating system commands on the underlying host. This issue is fixed in FileMaker Cloud 2.22.0.5.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43680">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-46295 – Apache Commons Text versions prior to 1.10.0 included interpolation features tha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46295</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46295</guid>
    <pubDate>Tue, 16 Dec 2025 18:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-46295</strong></p>
  <p>Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrusted input into the text-substitution API. Because some interpolators could trigger actions like executing commands or accessing external resources, an attacker could potentially achieve remote code execution. This vulnerability has been fully addressed in FileMaker Serv…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46295">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-27790 – Claris International has resolved an issue of potentially allowing unauthorized ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27790</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27790</guid>
    <pubDate>Tue, 14 May 2024 15:13:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-27790</strong></p>
  <p>Claris International has resolved an issue of potentially allowing unauthorized access to records stored in databases hosted on FileMaker Server. This issue has been fixed in FileMaker Server 20.3.2 by validating transactions before replying to client requests.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27790">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-42920 – Claris International has fixed a dylib hijacking vulnerability in the FileMaker ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-42920</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-42920</guid>
    <pubDate>Tue, 19 Mar 2024 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-42920</strong></p>
  <p>Claris International has fixed a dylib hijacking vulnerability in the FileMaker Pro.app and Claris Pro.app versions on macOS.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-42920">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-8347 – An Authentication Bypass vulnerability exists in the MatchPasswordData function ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-8347</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-8347</guid>
    <pubDate>Tue, 11 Feb 2020 14:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-8347</strong></p>
  <p>An Authentication Bypass vulnerability exists in the MatchPasswordData function in DBEngine.dll in Filemaker Pro 13.03 and Filemaker Pro Advanced 12.04, which could let a malicious user obtain elevated privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-8347">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-1208 – The server in Apple FileMaker before 14.0.4 on OS X allows remote attackers to r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-1208</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-1208</guid>
    <pubDate>Sat, 14 May 2016 15:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-1208</strong></p>
  <p>The server in Apple FileMaker before 14.0.4 on OS X allows remote attackers to read PHP source code via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-1208">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2000-0386 – FileMaker Pro 5 Web Companion allows remote attackers to send anonymous or forge...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2000-0386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2000-0386</guid>
    <pubDate>Tue, 02 May 2000 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2000-0386</strong></p>
  <p>FileMaker Pro 5 Web Companion allows remote attackers to send anonymous or forged email.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2000-0386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2000-0123 – The shopping cart application provided with Filemaker allows remote users to mod...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2000-0123</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2000-0123</guid>
    <pubDate>Tue, 01 Feb 2000 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2000-0123</strong></p>
  <p>The shopping cart application provided with Filemaker allows remote users to modify sensitive purchase information via hidden form fields.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2000-0123">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
