← Vulnerability feed

Vulnerability record · CVE-2025-46295 · published 16 December 2025

CVE-2025-46295: Claris filemaker server code injection vulnerability

Claris · Filemaker Server

Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrusted input into the text-substitution API. Because some interpolators could trigger actions like executing commands or accessing external resources, an attacker could potentially achieve remote code execution. This vulnerability has been fully addressed in FileMaker Server 22.0.4.

9.8 CVSS 3.1 Critical EPSS 1.0% · top 37.3% CWE-94 · Code injection
9.8CVSS 3.1 base score
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrusted input into the text-substitution API. Because some interpolators could trigger actions like executing commands or accessing external resources, an attacker could potentially achieve remote code execution. This vulnerability has been fully addressed in FileMaker Server 22.0.4.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-46295 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2024-27790Claris filemaker server improper access control vulnerabilityClaris International has resolved an issue of potentially allowing unauthorized access to records stored in databases hosted on FileMaker Server. Thi…EPSS 0.46%6.1CVE-2025-46320Claris filemaker server cross-site scripting vulnerabilityA cross-site scripting (XSS) vulnerability in a FileMaker WebDirect custom homepage could lead to unauthorized access and remote code execution. This…EPSS 0.22%6.1CVE-2024-27794Claris filemaker server cross-site scripting vulnerabilityClaris FileMaker Server before version 20.3.2 was susceptible to a reflected Cross-Site Scripting vulnerability due to an improperly handled paramete…EPSS 0.31%5.5CVE-2021-44147Claris filemaker pro xml external entity (xxe) vulnerabilityAn XML External Entity issue in Claris FileMaker Pro and Server (including WebDirect) before 19.4.1 allows a remote attacker to disclose local files …EPSS 1.2%5.4CVE-2025-46296Claris filemaker server improper authorization vulnerabilityAn authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privileges to access administrative …EPSS 0.17%5.3CVE-2025-46294Claris filemaker server information exposure vulnerabilityTo enhance security, the FileMaker Server 22.0.4 installer now includes an option to disable IIS short filename enumeration by setting NtfsDisable8do…EPSS 0.23%4.9CVE-2026-43752Claris filemaker server unrestricted file upload vulnerabilityAn authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Sour…EPSS 0.49%4.9CVE-2023-42955Claris filemaker server insufficiently protected credentials vulnerabilityClaris International has successfully resolved an issue of potentially exposing password information to front-end websites when signed in to the Admi…EPSS 0.45%

Source: NIST National Vulnerability Database (record CVE-2025-46295), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.