Fortinet Fortios vulnerabilities
282 known vulnerabilities affecting fortinet/fortios.
Total CVEs
282
CISA KEV
20
actively exploited
Public exploits
25
Exploited in wild
27
Severity breakdown
CRITICAL25HIGH88MEDIUM158LOW11
Vulnerabilities
Page 12 of 15
CVE-2017-14185P4MEDIUMCVSS 5.3≥ 5.2.0, ≤ 5.2.13≥ 5.4.0, ≤ 5.4.8+1 more2018-05-25
CVE-2017-14185 [MEDIUM] CWE-200 CVE-2017-14185: An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8 and 5.2 a
An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8 and 5.2 all versions allows SSL VPN web portal users to access internal FortiOS configuration information (eg:addresses) via specifically crafted URLs inside the SSL-VPN web portal.
nvd
CVE-2022-40680P4MEDIUMCVSS 5.4≥ 6.0.7, ≤ 6.0.15≥ 6.2.2, ≤ 6.2.12+2 more2022-12-06
CVE-2022-40680 [MEDIUM] CWE-79 CVE-2022-40680: A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet F
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiOS 6.0.7 - 6.0.15, 6.2.2 - 6.2.12, 6.4.0 - 6.4.9 and 7.0.0 - 7.0.3 allows a privileged attacker to execute unauthorized code or commands via storing malicious payloads in replacement messages.
nvd
CVE-2023-36555P4MEDIUMCVSS 5.4≥ 7.2.0, ≤ 7.2.42023-10-10
CVE-2023-36555 [MEDIUM] CWE-80 CVE-2023-36555: An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiOS
An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiOS 7.2.0 - 7.2.4 allows an attacker to execute unauthorized code or commands via the SAML and Security Fabric components.
nvd
CVE-2024-26015P4MEDIUMCVSS 4.7≥ 7.0.0, ≤ 7.0.15≥ 7.2.0, ≤ 7.2.8+1 more2024-07-09
CVE-2024-26015 [MEDIUM] CWE-1389 CVE-2024-26015: An incorrect parsing of numbers with different radices vulnerability [CWE-1389] in FortiProxy versio
An incorrect parsing of numbers with different radices vulnerability [CWE-1389] in FortiProxy version 7.4.3 and below, version 7.2.10 and below, version 7.0.17 and below and FortiOS version 7.4.3 and below, version 7.2.8 and below, version 7.0.15 and below IP address validation feature may permit an unauthenticated attacker to bypass the IP blockli
nvd
CVE-2025-43892P4MEDIUMCVSS 4.3≥ 7.2.0, ≤ 7.2.13≥ 7.4.0, ≤ 7.4.8+2 more2026-07-14
CVE-2025-43892 [MEDIUM] CWE-126 CVE-2025-43892: A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.
A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request.
nvd
CVE-2012-0941P4MEDIUMCVSS 6.1≥ 4.3.0, < 4.3.62018-02-08
CVE-2012-0941 [MEDIUM] CWE-79 CVE-2012-0941: Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiGate UTM WAF appliances with Fo
Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiGate UTM WAF appliances with FortiOS 4.3.x before 4.3.6 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) Endpoint Monitor, (2) Dialup List, or (3) Log&Report Display modules, or the fields_sorted_opt parameter to (4) user/auth/list or (5) end
nvd
CVE-2017-3127P4MEDIUMCVSS 6.1v5.2.0v5.2.1+9 more2017-06-01
CVE-2017-3127 [MEDIUM] CWE-79 CVE-2017-3127: A Cross-Site Scripting vulnerability in Fortinet FortiGate 5.2.0 through 5.2.10 allows attacker to e
A Cross-Site Scripting vulnerability in Fortinet FortiGate 5.2.0 through 5.2.10 allows attacker to execute unauthorized code or commands via the srcintf parameter during Firewall Policy Creation.
nvd
CVE-2019-5586P4MEDIUMCVSS 6.1≥ 5.2.0, ≤ 6.0.42019-06-04
CVE-2019-5586 [MEDIUM] CWE-79 CVE-2019-5586: A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 5.2.0 to 5.6.10, 6.0.0 to 6
A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 5.2.0 to 5.6.10, 6.0.0 to 6.0.4 under SSL VPN web portal may allow an attacker to execute unauthorized malicious script code via the "param" parameter of the error process HTTP requests.
nvd
CVE-2019-5588P4MEDIUMCVSS 6.1≥ 6.0.0, ≤ 6.0.42019-06-04
CVE-2019-5588 [MEDIUM] CWE-79 CVE-2019-5588: A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4 under SSL VP
A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4 under SSL VPN web portal may allow an attacker to execute unauthorized malicious script code via the "err" parameter of the error process HTTP requests.
nvd
CVE-2015-5965P4MEDIUMCVSS 5.0≤ 4.3.122015-08-11
CVE-2015-5965 [MEDIUM] CWE-20 CVE-2015-5965: The SSL-VPN feature in Fortinet FortiOS before 4.3.13 only checks the first byte of the TLS MAC in f
The SSL-VPN feature in Fortinet FortiOS before 4.3.13 only checks the first byte of the TLS MAC in finished messages, which makes it easier for remote attackers to spoof encrypted content via a crafted MAC field.
nvd
CVE-2006-3222P4MEDIUMCVSS 5.0v2.5_0mr4v2.8_mr10+7 more2006-06-24
CVE-2006-3222 [MEDIUM] CVE-2006-3222: The FTP proxy module in Fortinet FortiOS (FortiGate) before 2.80 MR12 and 3.0 MR2 allows remote atta
The FTP proxy module in Fortinet FortiOS (FortiGate) before 2.80 MR12 and 3.0 MR2 allows remote attackers to bypass anti-virus scanning via the Enhanced Passive (EPSV) FTP mode.
nvd
CVE-2017-7735P4MEDIUMCVSS 5.4v5.2.0v5.2.1+15 more2017-09-12
CVE-2017-7735 [MEDIUM] CWE-79 CVE-2017-7735: A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.2.0 through 5.2.11 and 5.4.0 thr
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.2.0 through 5.2.11 and 5.4.0 through 5.4.4 allows attackers to execute unauthorized code or commands via the "Groups" input while creating or editing User Groups.
nvd
CVE-2018-13365P4MEDIUMCVSS 5.3≤ 5.6.5≥ 5.6.6, ≤ 6.0.12019-05-29
CVE-2018-13365 [MEDIUM] CWE-200 CVE-2018-13365: An Information Exposure vulnerability in Fortinet FortiOS 6.0.1, 5.6.5 and below, allow attackers to
An Information Exposure vulnerability in Fortinet FortiOS 6.0.1, 5.6.5 and below, allow attackers to learn private IP as well as the hostname of FortiGate via Application Control Block page.
nvd
CVE-2019-15706P4MEDIUMCVSS 5.4≥ 5.6.0, < 5.6.13≥ 6.0.0, < 6.0.9+4 more2025-03-17
CVE-2019-15706 [MEDIUM] CWE-79 CVE-2019-15706: An improper neutralization of input during web page generation in the SSL VPN portal of FortiProxy v
An improper neutralization of input during web page generation in the SSL VPN portal of FortiProxy version 2.0.0, version 1.2.9 and below and FortiOS version 6.2.1 and below, version 6.0.8 and below, version 5.6.12 may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS).
nvd
CVE-2022-22306P4MEDIUMCVSS 5.3≥ 6.0.0, ≤ 6.0.14≥ 6.2.0, ≤ 6.2.10+2 more2022-05-24
CVE-2022-22306 [MEDIUM] CWE-295 CVE-2022-22306: An improper certificate validation vulnerability [CWE-295] in FortiOS 6.0.0 through 6.0.14, 6.2.0 th
An improper certificate validation vulnerability [CWE-295] in FortiOS 6.0.0 through 6.0.14, 6.2.0 through 6.2.10, 6.4.0 through 6.4.8, 7.0.0 may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication between the FortiGate and some peers such as private SDNs and external cloud platforms.
nvd
CVE-2024-23112P4MEDIUMCVSS 4.3≥ 6.4.7, ≤ 6.4.14≥ 7.0.1, ≤ 7.0.13+2 more2024-03-12
CVE-2024-23112 [MEDIUM] CWE-639 CVE-2024-23112: An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiOS version 7.4.0
An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiOS version 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.1 through 7.0.13, 6.4.7 through 6.4.14, and FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14 SSL-VPN may allow an authenticated attacker to gain access to another user’s bookmar
nvd
CVE-2024-47569P4MEDIUMCVSS 4.3≥ 6.0.0, < 6.4.16≥ 7.0.0, < 7.0.16+7 more2025-10-14
CVE-2024-47569 [MEDIUM] CWE-201 CVE-2024-47569: A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 throug
A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7.2.0 through 7.2.6, FortiMail 7.0 all versions, FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiNDR 7.6.0 through 7.6.1, FortiNDR 7.4.0 through 7.4.8, FortiNDR 7.2 al
nvd
CVE-2025-25255P4MEDIUMCVSS 4.3≥ 7.6.0, < 7.6.4≥ 7.6.0, ≤ 7.6.32025-10-14
CVE-2025-25255 [MEDIUM] CWE-358 CVE-2025-25255: An Improperly Implemented Security Check for Standard vulnerability [CWE-358] vulnerability in Forti
An Improperly Implemented Security Check for Standard vulnerability [CWE-358] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.11, FortiProxy 7.2 all versions, FortiProxy 7.0.1 through 7.0.22 may allow an unauthenticated proxy user to bypass the domain fronting protection feature via
nvd
CVE-2025-54822P4MEDIUMCVSS 4.3≥ 7.0.0, < 7.2.9≥ 7.4.0, < 7.4.2+3 more2025-10-14
CVE-2025-54822 [MEDIUM] CWE-285 CVE-2025-54822: An improper authorization vulnerability [CWE-285] vulnerability in Fortinet FortiOS 7.4.0 through 7.
An improper authorization vulnerability [CWE-285] vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.8, FortiOS 7.0.0 through 7.0.11, FortiProxy 7.4.0 through 7.4.8, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions, FortiProxy 2.0 all versions allows an authenticated attacker to access static files of others VDO
nvd
CVE-2026-59840P4MEDIUMCVSS 4.3≥ 7.2.0, < 7.4.9≥ 7.6.0, ≤ 7.6.2+4 more2026-07-14
CVE-2026-59840 [MEDIUM] CWE-126 CVE-2026-59840: A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.
A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4.0 through 7.4.13, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions may allow attacker to information disclosure via
nvd