VYPR

Filemaker Server

by Filemaker

CVEs (5)

  • CVE-2025-46295CriDec 16, 2025
    risk 0.64cvss 9.8epss 0.01

    Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrusted input into the text-substitution API. Because some interpolators could trigger actions like executing commands or accessing external resources, an…

  • CVE-2026-86934CriSep 23, 2026
    risk 0.59cvss 9.1epss 0.00

    An authorization bypass vulnerability in the FileMaker Server Web Publishing Engine allowed requests containing an extended privilege header to bypass the disabled Custom Web Publishing with XML setting and access the XML Web Publishing interface. This vulnerability is addressed…

  • CVE-2026-86926HigSep 23, 2026
    risk 0.51cvss 7.8epss 0.00

    A heap buffer overflow vulnerability in the FileMaker Server database engine block parsing routine allowed a maliciously crafted .fmp12 database file to cause memory corruption, potentially leading to arbitrary code execution. This vulnerability is addressed in FileMaker Server…

  • CVE-2026-43752MedJul 9, 2026
    risk 0.00cvss 4.9epss 0.00

    An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Source LLM setup feature in the Admin Console. This vulnerability has been addressed in FileMaker Server 26.0.1.

  • CVE-2007-6104Nov 23, 2007
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Instant Web Publishing feature in FileMaker Pro 7 and 8, Server 7 and 8, and Developer 7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.