CVE-2025-46320
Awaiting Analysis
Awaiting Analysis - Queue
Cross-Site Scripting in FileMaker WebDirect Enables Remote Code Execution
Publication date: 2026-02-24
Last updated on: 2026-02-25
Assigner: Apple Inc.
Description
Description
A cross-site scripting (XSS) vulnerability in a FileMaker WebDirect custom homepage could lead to unauthorized access and remote code execution. This vulnerability has been fully addressed in FileMaker Server 22.0.4 and FileMaker Server 21.1.7.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| claris | filemaker_server | to 21.1.7 (exc) |
| claris | filemaker_server | From 22.0.1 (inc) to 22.0.4 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-79 | The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. |