cbcvebase.

Fortinet Fortimail vulnerabilities

47 known vulnerabilities affecting fortinet/fortimail.

Total CVEs
47
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH15MEDIUM25

Vulnerabilities

Page 3 of 3
CVE-2024-47569P4MEDIUMCVSS 4.3≥ 7.0.0, < 7.2.7≥ 7.4.0, < 7.4.3+3 more2025-10-14
CVE-2024-47569 [MEDIUM] CWE-201 CVE-2024-47569: A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 throug A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7.2.0 through 7.2.6, FortiMail 7.0 all versions, FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiNDR 7.6.0 through 7.6.1, FortiNDR 7.4.0 through 7.4.8, FortiNDR 7.2 al
nvd
CVE-2023-36637P4MEDIUMCVSS 5.4≥ 7.0.1, ≤ 7.0.5v7.2.0+3 more2023-10-10
CVE-2023-36637 [MEDIUM] CWE-79 CVE-2023-36637: An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiMail v An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiMail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to inject HTML tags in FortiMail's calendar via input fields.
nvd
CVE-2024-40588P4MEDIUMCVSS 4.4≥ 6.4.0, < 7.4.4≥ 7.6.0, < 7.6.2+5 more2025-08-12
CVE-2024-40588 [MEDIUM] CWE-23 CVE-2024-40588: Multiple relative path traversal vulnerabilities [CWE-23] vulnerability in Fortinet FortiCamera 2.1 Multiple relative path traversal vulnerabilities [CWE-23] vulnerability in Fortinet FortiCamera 2.1 all versions, FortiCamera 2.0.0, FortiCamera 1.1 all versions, FortiCamera 1.0 all versions, FortiMail 7.6.0 through 7.6.1, FortiMail 7.4.0 through 7.4.3, FortiMail 7.2 all versions, FortiMail 7.0 all versions, FortiMail 6.4 all versions, FortiNDR 7.6.0
nvd
CVE-2025-54972P4MEDIUMCVSS 4.3≥ 7.0.0, < 7.4.6≥ 7.6.0, < 7.6.4+4 more2025-11-18
CVE-2025-54972 [MEDIUM] CWE-93 CVE-2025-54972: An improper neutralization of crlf sequences ('crlf injection') vulnerability in Fortinet FortiMail An improper neutralization of crlf sequences ('crlf injection') vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2 all versions, FortiMail 7.0 all versions may allow an attacker to inject headers in the response via convincing a user to click on a specifically crafted link
nvd
CVE-2015-3293P4MEDIUMCVSS 4.0v5.0.3v5.0.4+12 more2015-04-14
CVE-2015-3293 [MEDIUM] CWE-200 CVE-2015-3293: FortiMail 5.0.3 through 5.2.3 allows remote administrators to obtain credentials via the "diag debug FortiMail 5.0.3 through 5.2.3 allows remote administrators to obtain credentials via the "diag debug application httpd" command.
nvd
CVE-2014-8617P4MEDIUMCVSS 4.3≤ 4.3.8v5.0+15 more2015-03-04
CVE-2014-8617 [MEDIUM] CWE-79 CVE-2014-8617: Cross-site scripting (XSS) vulnerability in the Web Action Quarantine Release feature in the WebGUI Cross-site scripting (XSS) vulnerability in the Web Action Quarantine Release feature in the WebGUI in Fortinet FortiMail before 4.3.9, 5.0.x before 5.0.8, 5.1.x before 5.1.5, and 5.2.x before 5.2.3 allows remote attackers to inject arbitrary web script or HTML via the release parameter to module/releasecontrol.
nvd
CVE-2025-55717P4MEDIUMCVSS 4.0≥ 7.0.0, < 7.0.9≥ 7.2.0, < 7.2.8+6 more2026-03-10
CVE-2025-55717 [MEDIUM] CWE-312 CVE-2025-55717: A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet Forti A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0 all versions, FortiRecorder 6.4 all versions, FortiVoice 7.2.0, FortiVoice 7.0.
nvd