Fortinet Fortiproxy vulnerabilities
133 known vulnerabilities affecting fortinet/fortiproxy.
Total CVEs
133
CISA KEV
12
actively exploited
Public exploits
10
Exploited in wild
14
Severity breakdown
CRITICAL17HIGH41MEDIUM71LOW4
Vulnerabilities
Page 5 of 7
CVE-2025-67862P4MEDIUMCVSS 6.7≥ 7.0.0, ≤ 7.0.23≥ 7.2.0, < 7.2.15+5 more2026-06-09
CVE-2025-67862 [MEDIUM] CWE-1244 CVE-2025-67862: An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerabili
An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7
nvd
CVE-2023-33307P4MEDIUMCVSS 6.5≥ 7.0.0, ≤ 7.0.9≥ 7.2.0, ≤ 7.2.32023-06-16
CVE-2023-33307 [MEDIUM] CWE-476 CVE-2023-33307: A null pointer dereference in Fortinet FortiOS before 7.2.5 and before 7.0.11, FortiProxy before 7.2
A null pointer dereference in Fortinet FortiOS before 7.2.5 and before 7.0.11, FortiProxy before 7.2.3 and before 7.0.9 allows attacker to denial of sslvpn service via specifically crafted request in network parameter.
nvd
CVE-2022-23439P4MEDIUMCVSS 6.1≥ 2.0.0, < 7.0.5≥ 7.2.0, < 7.4.0+5 more2025-01-22
CVE-2022-23439 [MEDIUM] CWE-610 CVE-2022-23439: A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows
A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver
nvd
CVE-2023-47536P4MEDIUMCVSS 5.3≥ 2.0.0, ≤ 2.0.12≥ 7.0.0, ≤ 7.0.9+1 more2023-12-13
CVE-2023-47536 [MEDIUM] CWE-284 CVE-2023-47536: An improper access control vulnerability [CWE-284] in FortiOS version 7.2.0, version 7.0.13 and belo
An improper access control vulnerability [CWE-284] in FortiOS version 7.2.0, version 7.0.13 and below, version 6.4.14 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below may allow a remote unauthenticated attacker to bypass the firewall deny geolocalisation policy via timing the bypass with a GeoIP dat
nvd
CVE-2024-55599P4MEDIUMCVSS 5.3≥ 7.0.0, < 7.4.9≥ 7.6.0, < 7.6.2+4 more2025-07-08
CVE-2024-55599 [MEDIUM] CWE-358 CVE-2024-55599: An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiOS version 7.6
An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiOS version 7.6.0, version 7.4.7 and below, 7.0 all versions, 6.4 all versions and FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions may allow a remote unauthenticated user to bypass the DNS filter via Apple devices.
nvd
CVE-2021-44170P4MEDIUMCVSS 6.7≥ 1.0.0, ≤ 1.0.7≥ 1.1.0, ≤ 1.1.6+2 more2022-07-18
CVE-2021-44170 [MEDIUM] CWE-787 CVE-2021-44170: A stack-based buffer overflow vulnerability [CWE-121] in the command line interpreter of FortiOS bef
A stack-based buffer overflow vulnerability [CWE-121] in the command line interpreter of FortiOS before 7.0.4 and FortiProxy before 2.0.8 may allow an authenticated attacker to execute unauthorized code or commands via specially crafted command line arguments.
nvd
CVE-2021-43072P4MEDIUMCVSS 6.7≥ 1.0.0, < 2.0.9≥ 7.0.0, < 7.0.42023-07-18
CVE-2021-43072 [MEDIUM] CWE-120 CVE-2021-43072: A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiAnalyzer v
A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiAnalyzer version 7.0.2 and below, version 6.4.7 and below, version 6.2.9 and below, version 6.0.11 and below, version 5.6.11 and below, FortiManager version 7.0.2 and below, version 6.4.7 and below, version 6.2.9 and below, version 6.0.11 and below, version 5.6
nvd
CVE-2023-28002P4MEDIUMCVSS 6.7≥ 2.0.0, ≤ 2.0.13≥ 7.0.0, ≤ 7.0.13+2 more2023-11-14
CVE-2023-28002 [MEDIUM] CWE-354 CVE-2023-28002: An improper validation of integrity check value vulnerability [CWE-354] in FortiOS 7.2.0 through 7.2
An improper validation of integrity check value vulnerability [CWE-354] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.12, 6.4 all versions, 6.2 all versions, 6.0 all versions and VMs may allow a local attacker with admin privileges to boot a malicious image on the device and bypass the filesystem integrity check in place.
nvd
CVE-2025-47890P4MEDIUMCVSS 6.1≥ 7.0.0, < 7.6.4≥ 7.6.0, ≤ 7.6.3+3 more2025-10-14
CVE-2025-47890 [MEDIUM] CWE-601 CVE-2025-47890: An URL Redirection to Untrusted Site vulnerabilities [CWE-601] vulnerability in Fortinet FortiOS 7.6
An URL Redirection to Untrusted Site vulnerabilities [CWE-601] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions, FortiSA
nvd
CVE-2024-26008P4MEDIUMCVSS 5.3≥ 1.2.0, < 7.2.10≥ 7.4.0, < 7.4.4+5 more2025-10-14
CVE-2024-26008 [MEDIUM] CWE-754 CVE-2024-26008: An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7
An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7.4.0 through 7.4.3 and before 7.2.7, FortiProxy version 7.4.0 through 7.4.3 and before 7.2.9, FortiPAM before 1.2.0 and FortiSwitchManager version 7.2.0 through 7.2.3 and version 7.0.0 through 7.0.3 fgfm daemon may allow an unauthenticated attacker to
nvd
CVE-2024-52963P4MEDIUMCVSS 5.9≥ 7.4.0, ≤ 7.4.5≥ 7.2.0, ≤ 7.2.13+2 more2025-01-14
CVE-2024-52963 [MEDIUM] CWE-787 CVE-2024-52963: A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10,
A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4.0 through 6.4.15 allows attacker to trigger a denial of service via specially crafted packets.
nvd
CVE-2023-41675P4MEDIUMCVSS 5.3≥ 7.0.0, ≤ 7.0.8v7.2.0+3 more2023-10-10
CVE-2023-41675 [MEDIUM] CWE-416 CVE-2023-41675: A use after free vulnerability [CWE-416] in FortiOS version 7.2.0 through 7.2.4 and version 7.0.0 th
A use after free vulnerability [CWE-416] in FortiOS version 7.2.0 through 7.2.4 and version 7.0.0 through 7.0.10 and FortiProxy version 7.2.0 through 7.2.2 and version 7.0.0 through 7.0.8 may allow an unauthenticated remote attacker to crash the WAD process via multiple crafted packets reaching proxy policies or firewall policies with proxy mode alo
nvd
CVE-2022-42472P4MEDIUMCVSS 5.4≥ 1.1.0, ≤ 1.1.6≥ 1.2.0, ≤ 1.2.13+5 more2023-02-16
CVE-2022-42472 [MEDIUM] CWE-113 CVE-2022-42472: A improper neutralization of crlf sequences in http headers ('http response splitting') in Fortinet
A improper neutralization of crlf sequences in http headers ('http response splitting') in Fortinet FortiOS versions 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.11, 6.2.0 through 6.2.12, 6.0.0 through 6.0.16, FortiProxy 7.2.0 through 7.2.1, 7.0.0 through 7.0.7, 2.0.0 through 2.0.10, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6 may allow
nvd
CVE-2022-41329P4MEDIUMCVSS 5.3≥ 7.0.0, ≤ 7.0.8≥ 7.2.0, ≤ 7.2.22023-03-07
CVE-2022-41329 [MEDIUM] CWE-200 CVE-2022-41329: An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet Fo
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.7, FortiOS version 7.2.0 through 7.2.3 and 7.0.0 through 7.0.9 allows an unauthenticated attackers to obtain sensitive logging informations on the device via crafted HTTP GET requests.
nvd
CVE-2021-42757P4MEDIUMCVSS 6.7≥ 1.0.0, ≤ 2.0.7v7.0.0+5 more2021-12-08
CVE-2021-42757 [MEDIUM] CWE-120 CVE-2021-42757: A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 thr
A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code execution via specially crafted command line arguments.
nvd
CVE-2025-31366P4MEDIUMCVSS 6.1≥ 7.0.0, < 7.6.4≥ 7.6.0, ≤ 7.6.3+3 more2025-10-14
CVE-2025-31366 [MEDIUM] CWE-79 CVE-2025-31366: An Improper Neutralization of Input During Web Page Generation vulnerability [CWE-79] vulnerability
An Improper Neutralization of Input During Web Page Generation vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions, FortiProxy 7.0
nvd
CVE-2026-23573P4MEDIUMCVSS 6.1≥ 7.2.0, < 7.2.10≥ 7.4.0, < 7.4.4+3 more2026-07-14
CVE-2026-23573 [MEDIUM] CWE-79 CVE-2026-23573: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.8.0, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1
nvd
CVE-2026-59839P4MEDIUMCVSS 5.5≥ 7.0.0, < 7.4.14≥ 7.6.0, < 7.6.6+4 more2026-07-14
CVE-2026-59839 [MEDIUM] CWE-22 CVE-2026-59839: A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fo
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.8.0, FortiPAM 1.7.0 through 1.7.2, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM
nvd
CVE-2023-22641P4MEDIUMCVSS 5.4≥ 1.0.0, ≤ 2.0.12≥ 7.0.0, < 7.0.9+6 more2023-04-11
CVE-2023-22641 [MEDIUM] CWE-601 CVE-2023-22641: A url redirection to untrusted site ('open redirect') in Fortinet FortiOS version 7.2.0 through 7.2.
A url redirection to untrusted site ('open redirect') in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.9, FortiOS versions 6.4.0 through 6.4.12, FortiOS all versions 6.2, FortiOS all versions 6.0, FortiProxy version 7.2.0 through 7.2.2, FortiProxy version 7.0.0 through 7.0.8, FortiProxy all versions 2.0, FortiProxy
nvd
CVE-2021-26092P4MEDIUMCVSS 6.1≥ 1.2.0, ≤ 1.2.9v2.0.0+1 more2022-02-24
CVE-2021-26092 [MEDIUM] CWE-79 CVE-2021-26092: Failure to sanitize input in the SSL VPN web portal of FortiOS 5.2.10 through 5.2.15, 5.4.0 through
Failure to sanitize input in the SSL VPN web portal of FortiOS 5.2.10 through 5.2.15, 5.4.0 through 5.4.13, 5.6.0 through 5.6.14, 6.0.0 through 6.0.12, 6.2.0 through 6.2.7, 6.4.0 through 6.4.4; and FortiProxy 1.2.0 through 1.2.9, 2.0.0 through 2.0.1 may allow a remote unauthenticated attacker to perform a reflected Cross-site Scripting (XSS) attack by
nvd