CVE-2025-46320Disclosure(claris / filemaker_server)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch claris filemaker_server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A cross-site scripting (XSS) vulnerability in a FileMaker WebDirect custom homepage could lead to unauthorized access and remote code execution. This vulnerability has been fully addressed in FileMaker Server 22.0.4 and FileMaker Server 21.1.7.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • filemaker_server

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-25); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
filemaker_server

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-25: 2Mentions · 2026-03-05: 1Patch / Workaround · 2026-03-05: 1Technical Details · 2026-02-25: 2Technical Details · 2026-03-05: 102-2503-05
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-252
Disclosure2
2026-03-051
Patch1
Full discourse3 posts
  • Claris FileMaker 技術情報 公式アカウント@Claris_JP_FM
    Patch

    ナレッジベース が公開されました。 FileMaker WebDirect における XSS 脆弱性への対処 (CVE-2025-46320) https://support.claris.com/s/answerview?language=ja&anum=000049123 ナレッジベース へのご意見はページ下部の「このよくあるお問合せは役に立ちましたか?」からお願いします。

    Post summary

    The note links to a Claris support article that provides mitigation steps for the FileMaker WebDirect XSS vulnerability identified as CVE‑2025‑46320.

    02000339
    769 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-46320 A cross-site scripting (XSS) vulnerability in a FileMaker WebDirect custom homepage could lead to unauthorized access and remote code execution. This vulnerability ha… https://www.cve.org/CVERecord?id=CVE-2025-46320

    Post summary

    The text announces a new XSS vulnerability in FileMaker WebDirect that could lead to unauthorized access and remote code execution, but provides no PoC, exploit, or patch details.

    00000115
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-46320 Cross-Site Scripting Vulnerability in FileMaker WebDirect... https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-46320 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    A new CVE (CVE-2025-46320) for a cross‑site scripting vulnerability in FileMaker WebDirect is announced, with a link to details but no PoC, exploit, or patch information.

    0000052
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appclarisfilemaker_server---

Explore more