Fortinet Fortimail vulnerabilities
46 known vulnerabilities affecting fortinet/fortimail.
Total CVEs
46
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH14MEDIUM25
Vulnerabilities
Page 1 of 3
CVE-2025-55717MEDIUMCVSS 4.0≥ 7.0.0, < 7.0.9≥ 7.2.0, < 7.2.8+6 more2026-03-10
CVE-2025-55717 [MEDIUM] CWE-312 CVE-2025-55717: A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet Forti
A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0 all versions, FortiRecorder 6.4 all versions, FortiVoice 7.2.0, FortiVoice 7.0.
cvelistv5nvd
CVE-2025-54972MEDIUMCVSS 4.3≥ 7.0.0, < 7.4.6≥ 7.6.0, < 7.6.4+4 more2025-11-18
CVE-2025-54972 [MEDIUM] CWE-93 CVE-2025-54972: An improper neutralization of crlf sequences ('crlf injection') vulnerability in Fortinet FortiMail
An improper neutralization of crlf sequences ('crlf injection') vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2 all versions, FortiMail 7.0 all versions may allow an attacker to inject headers in the response via convincing a user to click on a specifically crafted link
cvelistv5nvd
CVE-2024-47569MEDIUMCVSS 4.3≥ 7.0.0, < 7.2.7≥ 7.4.0, < 7.4.3+3 more2025-10-14
CVE-2024-47569 [MEDIUM] CWE-201 CVE-2024-47569: A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 throug
A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7.2.0 through 7.2.6, FortiMail 7.0 all versions, FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiNDR 7.6.0 through 7.6.1, FortiNDR 7.4.0 through 7.4.8, FortiNDR 7.2 al
cvelistv5nvd
CVE-2024-40588MEDIUMCVSS 4.4≥ 6.4.0, < 7.4.4≥ 7.6.0, < 7.6.2+5 more2025-08-12
CVE-2024-40588 [MEDIUM] CWE-23 CVE-2024-40588: Multiple relative path traversal vulnerabilities [CWE-23] vulnerability in Fortinet FortiCamera 2.1
Multiple relative path traversal vulnerabilities [CWE-23] vulnerability in Fortinet FortiCamera 2.1 all versions, FortiCamera 2.0.0, FortiCamera 1.1 all versions, FortiCamera 1.0 all versions, FortiMail 7.6.0 through 7.6.1, FortiMail 7.4.0 through 7.4.3, FortiMail 7.2 all versions, FortiMail 7.0 all versions, FortiMail 6.4 all versions, FortiNDR 7.6.0
cvelistv5nvd
CVE-2025-32756CRITICALCVSS 9.8KEV≥ 7.0.0, < 7.0.9≥ 7.2.0, < 7.2.8+6 more2025-05-13
CVE-2025-32756 [CRITICAL] CWE-121 CVE-2025-32756: A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 th
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.7, FortiN
cvelistv5nvd
CVE-2023-33302HIGHCVSS 8.8≥ 5.4.0, ≤ 5.4.12≥ 6.0.0, < 6.0.11+10 more2025-03-31
CVE-2023-33302 [MEDIUM] CWE-120 CVE-2023-33302: A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiMail webm
A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiMail webmail and administrative interface version 6.4.0 through 6.4.4 and before 6.2.6 and FortiNDR administrative interface version 7.2.0 and before 7.1.0 allows an authenticated attacker with regular webmail access to trigger a buffer overflow and to possibly
cvelistv5nvd
CVE-2021-24008MEDIUMCVSS 5.3≥ 6.0.0, < 6.0.10≥ 6.2.0, < 6.2.5+1 more2025-03-28
CVE-2021-24008 [MEDIUM] CWE-200 CVE-2021-24008: An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497
An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiDDoS version 5.4.0, version 5.3.2 and below, version 5.2.0, version 5.1.0, version 5.0.0, version 4.7.0, version 4.6.0, version 4.5.0, version 4.4.2 and below, FortiDDoS-CM version 5.3.0, version 5.2.0, version 5.1.0, version 5.0.0, version
nvd
CVE-2021-26091HIGHCVSS 7.5≥ 6.2.0, < 6.4.5≥ 6.4.0, ≤ 6.4.4+2 more2025-03-24
CVE-2021-26091 [HIGH] CWE-338 CVE-2021-26091: A use of a cryptographically weak pseudo-random number generator vulnerability in the authenticator
A use of a cryptographically weak pseudo-random number generator vulnerability in the authenticator of the Identity Based Encryption service of FortiMail 6.4.0 through 6.4.4, and 6.2.0 through 6.2.7 may allow an unauthenticated attacker to infer parts of users authentication tokens and reset their credentials.
cvelistv5nvd
CVE-2023-47539CRITICALCVSS 9.8v7.4.02025-03-18
CVE-2023-47539 [CRITICAL] CWE-284 CVE-2023-47539: An improper access control vulnerability in FortiMail version 7.4.0 configured with RADIUS authentic
An improper access control vulnerability in FortiMail version 7.4.0 configured with RADIUS authentication and remote_wildcard enabled may allow a remote unauthenticated attacker to bypass admin login via a crafted HTTP request.
cvelistv5nvd
CVE-2024-46663MEDIUMCVSS 6.7≥ 6.4.0, < 7.2.7≥ 7.4.0, < 7.4.4+6 more2025-03-11
CVE-2024-46663 [MEDIUM] CWE-121 CVE-2024-46663: A stack-buffer overflow vulnerability [CWE-121] in Fortinet FortiMail CLI version 7.6.0 through 7.6.
A stack-buffer overflow vulnerability [CWE-121] in Fortinet FortiMail CLI version 7.6.0 through 7.6.1 and before 7.4.3 allows a privileged attacker to execute arbitrary code or commands via specifically crafted CLI commands.
cvelistv5nvd
CVE-2022-23439MEDIUMCVSS 6.1≥ 6.4.0, < 7.0.4≥ 7.0.0, ≤ 7.0.3+4 more2025-01-22
CVE-2022-23439 [MEDIUM] CWE-610 CVE-2022-23439: A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows
A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver
cvelistv5nvd
CVE-2024-56497MEDIUMCVSS 6.7≥ 6.4.0, < 6.4.8≥ 7.0.0, < 7.0.7+4 more2025-01-14
CVE-2024-56497 [MEDIUM] CWE-78 CVE-2024-56497: An improper neutralization of special elements used in an os command ('os command injection') in For
An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMail versions 7.2.0 through 7.2.4 and 7.0.0 through 7.0.6 and 6.4.0 through 6.4.7, FortiRecorder versions 7.0.0 and 6.4.0 through 6.4.4 allows attacker to execute unauthorized code or commands via the CLI.
cvelistv5nvd
CVE-2022-27488HIGHCVSS 8.8≥ 6.0.0, ≤ 6.0.12≥ 6.2.0, ≤ 6.2.9+2 more2023-12-13
CVE-2022-27488 [HIGH] CWE-352 CVE-2022-27488: A cross-site request forgery (CSRF) in Fortinet FortiVoiceEnterprise version 6.4.x, 6.0.x, FortiSwit
A cross-site request forgery (CSRF) in Fortinet FortiVoiceEnterprise version 6.4.x, 6.0.x, FortiSwitch version 7.0.0 through 7.0.4, 6.4.0 through 6.4.10, 6.2.0 through 6.2.7, 6.0.x, FortiMail version 7.0.0 through 7.0.3, 6.4.0 through 6.4.6, 6.2.x, 6.0.x FortiRecorder version 6.4.0 through 6.4.2, 6.0.x, 2.7.x, 2.6.x, FortiNDR version 1.x.x allows a re
cvelistv5nvd
CVE-2023-45582HIGHCVSS 7.3≥ 6.2.0, ≤ 6.2.9≥ 6.4.0, ≤ 6.4.8+3 more2023-11-14
CVE-2023-45582 [MEDIUM] CWE-307 CVE-2023-45582: An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiMail we
An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiMail webmail version 7.2.0 through 7.2.4, 7.0.0 through 7.0.6 and before 6.4.8 may allow an unauthenticated attacker to perform a brute force attack on the affected endpoints via repeated login attempts.
cvelistv5nvd
CVE-2023-36633MEDIUMCVSS 5.4≥ 6.0.0, < 7.0.6≥ 7.2.0, < 7.2.3+5 more2023-11-14
CVE-2023-36633 [MEDIUM] CWE-285 CVE-2023-36633: An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 a
An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to see and modify the title of address book folders of other users via crafted HTTP or HTTPs requests.
cvelistv5nvd
CVE-2023-36556HIGHCVSS 8.8≥ 6.0.0, ≤ 6.0.12≥ 6.2.0, ≤ 6.2.9+6 more2023-10-10
CVE-2023-36556 [HIGH] CWE-863 CVE-2023-36556: An incorrect authorization vulnerability [CWE-863] in FortiMail webmail version 7.2.0 through 7.2.2,
An incorrect authorization vulnerability [CWE-863] in FortiMail webmail version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.5 and below 6.4.7 allows an authenticated attacker to login on other users accounts from the same web domain via crafted HTTP or HTTPs requests.
cvelistv5nvd
CVE-2023-36637MEDIUMCVSS 5.4≥ 7.0.1, ≤ 7.0.5v7.2.0+3 more2023-10-10
CVE-2023-36637 [LOW] CWE-79 CVE-2023-36637: An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiMail v
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiMail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to inject HTML tags in FortiMail's calendar via input fields.
cvelistv5nvd
CVE-2022-29056MEDIUMCVSS 5.3≥ 6.0.0, < 6.0.10≥ 6.2.1, < 6.2.5+4 more2023-03-09
CVE-2022-29056 [LOW] CWE-307 CVE-2022-29056: A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet Fort
A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiMail version 6.4.0, version 6.2.0 through 6.2.4 and before 6.0.9 allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login form.
cvelistv5nvd
CVE-2022-26122HIGHCVSS 8.6≥ 6.0.0, ≤ 6.0.12≥ 6.2.0, ≤ 6.2.9+3 more2022-11-02
CVE-2022-26122 [MEDIUM] CWE-345 CVE-2022-26122: An insufficient verification of data authenticity vulnerability [CWE-345] in FortiClient, FortiMail
An insufficient verification of data authenticity vulnerability [CWE-345] in FortiClient, FortiMail and FortiOS AV engines version 6.2.168 and below and version 6.4.274 and below may allow an attacker to bypass the AV engine via manipulating MIME attachment with junk and pad characters in base64.
nvd
CVE-2022-39945MEDIUMCVSS 6.5≥ 6.0.0, ≤ 6.0.12≥ 6.2.0, ≤ 6.2.9+3 more2022-11-02
CVE-2022-39945 [MEDIUM] CWE-639 CVE-2022-39945: An improper access control vulnerability [CWE-284] in FortiMail 7.2.0, 7.0.0 through 7.0.3, 6.4 all
An improper access control vulnerability [CWE-284] in FortiMail 7.2.0, 7.0.0 through 7.0.3, 6.4 all versions, 6.2 all versions, 6.0 all versions may allow an authenticated admin user assigned to a specific domain to access and modify other domains information via insecure direct object references (IDOR).
nvd
1 / 3Next →