Fortinet Fortiproxy vulnerabilities
130 known vulnerabilities affecting fortinet/fortiproxy.
Total CVEs
130
CISA KEV
12
actively exploited
Public exploits
10
Exploited in wild
14
Severity breakdown
CRITICAL17HIGH39MEDIUM71LOW3
Vulnerabilities
Page 6 of 7
CVE-2025-25255P4MEDIUMCVSS 4.3≥ 7.0.1, < 7.6.4≥ 7.6.0, ≤ 7.6.3+3 more2025-10-14
CVE-2025-25255 [MEDIUM] CWE-358 CVE-2025-25255: An Improperly Implemented Security Check for Standard vulnerability [CWE-358] vulnerability in Forti
An Improperly Implemented Security Check for Standard vulnerability [CWE-358] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.11, FortiProxy 7.2 all versions, FortiProxy 7.0.1 through 7.0.22 may allow an unauthenticated proxy user to bypass the domain fronting protection feature via
nvd
CVE-2021-43081P4MEDIUMCVSS 6.1≥ 2.0.0, < 2.0.8≥ 7.0.0, < 7.0.22022-05-11
CVE-2021-43081 [MEDIUM] CWE-79 CVE-2021-43081: An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS ver
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.0.3 and below, 6.4.8 and below, 6.2.10 and below, 6.0.14 to 6.0.0. and in FortiProxy version 7.0.1 and below, 2.0.7 to 2.0.0 web filter override form may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests.
nvd
CVE-2022-41330P4MEDIUMCVSS 6.1≥ 7.0.0, < 7.0.8≥ 7.2.0, < 7.2.2+2 more2023-04-11
CVE-2022-41330 [MEDIUM] CWE-79 CVE-2022-41330: An improper neutralization of input during web page generation vulnerability ('Cross-site Scripting'
An improper neutralization of input during web page generation vulnerability ('Cross-site Scripting') [CWE-79] in Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9, version 6.4.0 through 6.4.11 and before 6.2.12 and FortiProxy version 7.2.0 through 7.2.1 and before 7.0.7 allows an unauthenticated attacker to perform an XSS att
nvd
CVE-2023-45586P4MEDIUMCVSS 5.0≥ 2.0.0, ≤ 2.0.12≥ 7.0.0, < 7.0.14+6 more2024-05-14
CVE-2023-45586 [MEDIUM] CWE-345 CVE-2023-45586: An insufficient verification of data authenticity vulnerability [CWE-345] in Fortinet FortiOS SSL-VP
An insufficient verification of data authenticity vulnerability [CWE-345] in Fortinet FortiOS SSL-VPN tunnel mode version 7.4.0 through 7.4.1, version 7.2.0 through 7.2.7 and before 7.0.12 & FortiProxy SSL-VPN tunnel mode version 7.4.0 through 7.4.1, version 7.2.0 through 7.2.7 and before 7.0.13 allows an authenticated VPN user to send (but not rece
nvd
CVE-2023-29175P4MEDIUMCVSS 4.8≥ 1.2.0, ≤ 1.2.13≥ 2.0.0, ≤ 2.0.12+2 more2023-06-13
CVE-2023-29175 [MEDIUM] CWE-295 CVE-2023-29175: An improper certificate validation vulnerability [CWE-295] in FortiOS 6.2 all versions, 6.4 all vers
An improper certificate validation vulnerability [CWE-295] in FortiOS 6.2 all versions, 6.4 all versions, 7.0.0 through 7.0.10, 7.2.0 and FortiProxy 1.2 all versions, 2.0 all versions, 7.0.0 through 7.0.9, 7.2.0 through 7.2.3 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between th
nvd
CVE-2023-29183P4MEDIUMCVSS 5.4≥ 7.0.0, < 7.0.11≥ 7.2.0, < 7.2.5+2 more2023-09-13
CVE-2023-29183 [MEDIUM] CWE-79 CVE-2023-29183: An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerabilit
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiProxy 7.2.0 through 7.2.4, 7.0.0 through 7.0.10 and FortiOS 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14 GUI may allow an authenticated attacker to trigger malicious JavaScript code execution
nvd
CVE-2022-40680P4MEDIUMCVSS 5.4≥ 7.0.0, ≤ 7.0.1≥ 2.0.0, ≤ 2.0.11+2 more2022-12-06
CVE-2022-40680 [MEDIUM] CWE-79 CVE-2022-40680: A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet F
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiOS 6.0.7 - 6.0.15, 6.2.2 - 6.2.12, 6.4.0 - 6.4.9 and 7.0.0 - 7.0.3 allows a privileged attacker to execute unauthorized code or commands via storing malicious payloads in replacement messages.
nvd
CVE-2024-26015P4MEDIUMCVSS 4.7≥ 7.0.0, ≤ 7.4.3≥ 7.4.0, ≤ 7.4.3+1 more2024-07-09
CVE-2024-26015 [MEDIUM] CWE-1389 CVE-2024-26015: An incorrect parsing of numbers with different radices vulnerability [CWE-1389] in FortiProxy versio
An incorrect parsing of numbers with different radices vulnerability [CWE-1389] in FortiProxy version 7.4.3 and below, version 7.2.10 and below, version 7.0.17 and below and FortiOS version 7.4.3 and below, version 7.2.8 and below, version 7.0.15 and below IP address validation feature may permit an unauthenticated attacker to bypass the IP blockli
nvd
CVE-2024-47569P4MEDIUMCVSS 4.3≥ 1.0.0, < 7.2.11≥ 7.4.0, < 7.4.5+3 more2025-10-14
CVE-2024-47569 [MEDIUM] CWE-201 CVE-2024-47569: A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 throug
A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7.2.0 through 7.2.6, FortiMail 7.0 all versions, FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiNDR 7.6.0 through 7.6.1, FortiNDR 7.4.0 through 7.4.8, FortiNDR 7.2 al
nvd
CVE-2025-43892P4MEDIUMCVSS 4.3≥ 7.2.0, ≤ 7.2.15≥ 7.4.0, ≤ 7.4.13+1 more2026-07-14
CVE-2025-43892 [MEDIUM] CWE-126 CVE-2025-43892: A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.
A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request.
nvd
CVE-2025-54822P4MEDIUMCVSS 4.3≥ 2.0.0, < 7.4.9≥ 7.4.0, ≤ 7.4.8+3 more2025-10-14
CVE-2025-54822 [MEDIUM] CWE-285 CVE-2025-54822: An improper authorization vulnerability [CWE-285] vulnerability in Fortinet FortiOS 7.4.0 through 7.
An improper authorization vulnerability [CWE-285] vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.8, FortiOS 7.0.0 through 7.0.11, FortiProxy 7.4.0 through 7.4.8, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions, FortiProxy 2.0 all versions allows an authenticated attacker to access static files of others VDO
nvd
CVE-2025-62826P4MEDIUMCVSS 4.3≥ 7.2.0, < 7.6.5≥ 7.6.0, ≤ 7.6.4+3 more2026-07-14
CVE-2025-62826 [MEDIUM] CWE-113 CVE-2025-62826: An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerabili
An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow an attacker able to intercept an
nvd
CVE-2019-15706P4MEDIUMCVSS 5.4≥ 1.2.0, ≤ 1.2.9v2.0.02025-03-17
CVE-2019-15706 [MEDIUM] CWE-79 CVE-2019-15706: An improper neutralization of input during web page generation in the SSL VPN portal of FortiProxy v
An improper neutralization of input during web page generation in the SSL VPN portal of FortiProxy version 2.0.0, version 1.2.9 and below and FortiOS version 6.2.1 and below, version 6.0.8 and below, version 5.6.12 may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS).
nvd
CVE-2021-22130P4MEDIUMCVSS 4.9≥ 1.0.0, ≤ 1.0.7≥ 1.1.0, ≤ 1.1.6+2 more2021-06-03
CVE-2021-22130 [MEDIUM] CWE-787 CVE-2021-22130: A stack-based buffer overflow vulnerability in FortiProxy physical appliance CLI 2.0.0 to 2.0.1, 1.2
A stack-based buffer overflow vulnerability in FortiProxy physical appliance CLI 2.0.0 to 2.0.1, 1.2.0 to 1.2.9, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 may allow an authenticated, remote attacker to perform a Denial of Service attack by running the `diagnose sys cpuset` with a large cpuset mask value. Fortinet is not aware of any successful exploitation of
nvd
CVE-2024-23112P4MEDIUMCVSS 4.3≥ 7.0.0, ≤ 7.0.14≥ 7.2.0, ≤ 7.2.8+1 more2024-03-12
CVE-2024-23112 [MEDIUM] CWE-639 CVE-2024-23112: An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiOS version 7.4.0
An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiOS version 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.1 through 7.0.13, 6.4.7 through 6.4.14, and FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14 SSL-VPN may allow an authenticated attacker to gain access to another user’s bookmar
nvd
CVE-2025-62675P4MEDIUMCVSS 4.3≥ 7.2.0, < 7.6.5≥ 7.6.0, ≤ 7.6.4+3 more2026-07-14
CVE-2025-62675 [MEDIUM] CWE-113 CVE-2025-62675: An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerabili
An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow an attacker in possession of a v
nvd
CVE-2026-59840P4MEDIUMCVSS 4.3≥ 7.2.0, < 7.4.14≥ 7.6.0, < 7.6.6+4 more2026-07-14
CVE-2026-59840 [MEDIUM] CWE-126 CVE-2026-59840: A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.
A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4.0 through 7.4.13, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions may allow attacker to information disclosure via
nvd
CVE-2023-46715P4MEDIUMCVSS 4.3≥ 7.4.0, ≤ 7.4.1≥ 7.2.0, ≤ 7.2.6+1 more2025-01-14
CVE-2023-46715 [MEDIUM] CWE-346 CVE-2023-46715: An origin validation error [CWE-346] vulnerability in Fortinet FortiOS IPSec VPN version 7.4.0 thro
An origin validation error [CWE-346] vulnerability in Fortinet FortiOS IPSec VPN version 7.4.0 through 7.4.1 and version 7.2.6 and below allows an authenticated IPSec VPN user with dynamic IP addressing to send (but not receive) packets spoofing the IP of another user via crafted network packets.
nvd
CVE-2024-33510P4MEDIUMCVSS 4.3≥ 7.0.0, < 7.0.17≥ 7.2.0, < 7.2.10+4 more2024-11-12
CVE-2024-33510 [MEDIUM] CWE-358 CVE-2024-33510: An improper neutralization of special elements in output used by a downstream component ('Injection'
An improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability [CWE-74] in FortiOS version 7.4.3 and below, version 7.2.8 and below, version 7.0.16 and below; FortiProxy version 7.4.3 and below, version 7.2.9 and below, version 7.0.16 and below; FortiSASE version 24.2.b SSL-VPN web user interface
nvd
CVE-2025-31514P4MEDIUMCVSS 4.3≥ 7.0.0, < 7.6.4≥ 7.6.0, ≤ 7.6.3+3 more2025-10-14
CVE-2025-31514 [MEDIUM] CWE-532 CVE-2025-31514: A insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.6.0 through 7
A insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.13, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions may allow attacker
nvd