← Vulnerability feed

Vulnerability record · CVE-2021-44147 · published 22 November 2021

CVE-2021-44147: Claris filemaker pro xml external entity (xxe) vulnerability

Claris · Filemaker Pro

An XML External Entity issue in Claris FileMaker Pro and Server (including WebDirect) before 19.4.1 allows a remote attacker to disclose local files via a crafted XML/Excel document and perform server-side request forgery attacks.

5.5 CVSS 3.1 Medium EPSS 1.2% · top 33.8% CWE-611 · XML external entity (XXE)
5.5CVSS 3.1 base score, v2 4.3
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An XML External Entity issue in Claris FileMaker Pro and Server (including WebDirect) before 19.4.1 allows a remote attacker to disclose local files via a crafted XML/Excel document and perform server-side request forgery attacks.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-44147 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-46295Claris filemaker server code injection vulnerabilityApache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrusted input into the t…EPSS 1.0%7.8CVE-2023-42920Claris pro uncontrolled search path element vulnerabilityClaris International has fixed a dylib hijacking vulnerability in the FileMaker Pro.app and Claris Pro.app versions on macOS.EPSS 0.18%7.8CVE-2014-8347Claris filemaker pro improper authentication vulnerabilityAn Authentication Bypass vulnerability exists in the MatchPasswordData function in DBEngine.dll in Filemaker Pro 13.03 and Filemaker Pro Advanced 12.…EPSS 1.4%7.5CVE-2024-27790Claris filemaker server improper access control vulnerabilityClaris International has resolved an issue of potentially allowing unauthorized access to records stored in databases hosted on FileMaker Server. Thi…EPSS 0.46%6.1CVE-2025-46320Claris filemaker server cross-site scripting vulnerabilityA cross-site scripting (XSS) vulnerability in a FileMaker WebDirect custom homepage could lead to unauthorized access and remote code execution. This…EPSS 0.22%6.1CVE-2024-27794Claris filemaker server cross-site scripting vulnerabilityClaris FileMaker Server before version 20.3.2 was susceptible to a reflected Cross-Site Scripting vulnerability due to an improperly handled paramete…EPSS 0.31%5.4CVE-2025-46296Claris filemaker server improper authorization vulnerabilityAn authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privileges to access administrative …EPSS 0.17%5.3CVE-2025-46294Claris filemaker server information exposure vulnerabilityTo enhance security, the FileMaker Server 22.0.4 installer now includes an option to disable IIS short filename enumeration by setting NtfsDisable8do…EPSS 0.23%

Source: NIST National Vulnerability Database (record CVE-2021-44147), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.