CVE-2025-58324
published 2025-10-14CVE-2025-58324: An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSIEM 7.2.0 through 7.2.2, 7.1 all versions, 7.0 all versions, 6.7…
PriorityP421medium4.8CVSS 3.1
AVNACLPRHUIRSCCLILAN
EPSS
0.25%
16.4th percentile
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSIEM 7.2.0 through 7.2.2, 7.1 all versions, 7.0 all versions, 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack via crafted HTTP requests.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortisiem | — | — |
| fortinet | fortisiem | >= 6.2.0 < 7.2.3 | 7.2.3 |
| fortinet | fortisiem | 6.2.0 – 6.2.1 | — |
| fortinet | fortisiem | 6.3.0 – 6.3.3 | — |
| fortinet | fortisiem | 6.4.0 – 6.4.4 | — |
| fortinet | fortisiem | 6.5.0 – 6.5.3 | — |
| fortinet | fortisiem | 6.6.0 – 6.6.5 | — |
| fortinet | fortisiem | 6.7.0 – 6.7.10 | — |
| fortinet | fortisiem | 7.0.0 – 7.0.4 | — |
| fortinet | fortisiem | 7.1.0 – 7.1.9 | — |
| fortinet | fortisiem | 7.2.0 – 7.2.2 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vjwm-vh33-rm7v: An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSIEM 7
ghsa_unreviewed·2025-10-14
CVE-2025-58324 [MEDIUM] CWE-79 GHSA-vjwm-vh33-rm7v: An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSIEM 7
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSIEM 7.2.0 through 7.2.2, 7.1 all versions, 7.0 all versions, 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack via crafted HTTP requests.
Fortinet
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSIEM 7.2.0 through 7.2.2,...
vendor_fortinet·2025-10-14·CVSS 6.4
CVE-2025-58324 [MEDIUM] CWE-79 An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSIEM 7.2.0 through 7.2.2,...
FG-IR-24-280: An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSIEM 7.2.0 through 7.2.2,...
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSIEM 7.2.0 through 7.2.2, 7.1 all versions, 7.0 all versions, 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack via crafted HTTP requests.
CVEs: CVE-2025-58324
CWEs: CWE-79
CVSS: 6.4 (medium)
Affected products: FortiSIEM
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-25972 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.9
CVE-2026-25972 [CRITICAL] CVE-2026-25972 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25972 :
FortiSIEM vulnerability analysis and mitigation
An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4 may allow a remote unauthenticated attacker to provide arbitrary data enabling a social engineering attack via spoofed URL parameters.
Source : NVD
## 6.1
Score
Published March 10, 2026
Severity MEDIUM
CNA Score 4.3
Affected Technologies
FortiSIEM
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 14.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:fortinet:fortisiem
Sources
Linux Severity MEDIUM Has Fix Added at: Mar 10, 2026
Wiz
CVE-2025-64155 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.9
CVE-2025-64155 [CRITICAL] CVE-2025-64155 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64155 :
FortiSIEM vulnerability analysis and mitigation
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.1.0 through 7.1.8, FortiSIEM 7.0.0 through 7.0.4, FortiSIEM 6.7.0 through 6.7.10 may allow an attacker to execute unauthorized code or commands via crafted TCP requests.
Source : NVD
## 9.8
Score
Published January 13, 2026
Severity CRITICAL
CNA Score 9.8
Affected Technologies
FortiSIEM
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 23.2
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
cpe:2.3:a:fortinet:fortisiem
Sour
2025-10-14
Published