Medium severity6.1NVD Advisory· Published Feb 24, 2026· Updated Jun 17, 2026
CVE-2025-46320
CVE-2025-46320
Description
A cross-site scripting (XSS) vulnerability in a FileMaker WebDirect custom homepage could lead to unauthorized access and remote code execution. This vulnerability has been fully addressed in FileMaker Server 22.0.4 and FileMaker Server 21.1.7.
Affected products
4cpe:2.3:a:claris:filemaker_server:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:claris:filemaker_server:*:*:*:*:*:*:*:*range: <21.1.7
- (no CPE)
- (no CPE)range: unspecified
Patches
Vulnerability mechanics
References
1- support.claris.com/s/answerviewnvdVendor Advisory
News mentions
0No linked articles in our index yet.