Fortinet Fortisandbox vulnerabilities

51 known vulnerabilities affecting fortinet/fortisandbox.

Total CVEs
51
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH23MEDIUM25LOW1

Vulnerabilities

Page 1 of 3
CVE-2025-53608MEDIUMCVSS 4.8≥ 4.0.0, < 4.4.8≥ 5.0.0, < 5.0.3+4 more2026-03-10
CVE-2025-53608 [MEDIUM] CWE-79 CVE-2025-53608: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an authenticated privileged attacker to execute code via crafted requests.
cvelistv5nvd
CVE-2025-52436CRITICALCVSS 9.6≥ 4.0.0, < 4.4.8≥ 5.0.0, < 5.0.2+4 more2026-02-10
CVE-2025-52436 [HIGH] CWE-79 CVE-2025-52436: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an unauthenticated attacker to execute commands via crafted requests.
cvelistv5nvd
CVE-2025-67685LOWCVSS 3.8≥ 4.0.0, < 5.0.5≥ 5.0.0, ≤ 5.0.4+3 more2026-01-13
CVE-2025-67685 [LOW] CWE-918 CVE-2025-67685: A Server-Side Request Forgery (SSRF) vulnerability [CWE-918] vulnerability in Fortinet FortiSandbox A Server-Side Request Forgery (SSRF) vulnerability [CWE-918] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4, FortiSandbox 4.4 all versions, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an authenticated attacker to proxy internal requests limited to plaintext endpoints only via crafted HTTP requests.
cvelistv5nvd
CVE-2025-53679HIGHCVSS 7.2≥ 4.0.0, < 4.4.8≥ 5.0.0, < 5.0.3+4 more2025-12-09
CVE-2025-53679 [HIGH] CWE-78 CVE-2025-53679: An improper neutralization of special elements used in an OS command ('OS Command Injection') vulner An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions, FortiSandbox Cloud 24.1, FortiSandbox Cloud 23 all versions allows a remote privi
cvelistv5nvd
CVE-2025-53949HIGHCVSS 8.8≥ 4.0.0, ≤ 4.0.6≥ 4.2.0, ≤ 4.2.8+3 more2025-12-09
CVE-2025-53949 [HIGH] CWE-78 CVE-2025-53949: An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an authenticated attacker to execute unauthorized code on the underlying
cvelistv5nvd
CVE-2025-54353MEDIUMCVSS 6.1≥ 4.0.0, ≤ 4.0.6≥ 4.2.0, ≤ 4.2.8+3 more2025-12-09
CVE-2025-54353 [MEDIUM] CWE-79 CVE-2025-54353: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an attacker to perform an XSS attack via crafted HTTP requests.
cvelistv5nvd
CVE-2025-46215MEDIUMCVSS 5.3≥ 4.0.0, < 4.4.8≥ 5.0.0, < 5.0.2+4 more2025-11-18
CVE-2025-46215 [MEDIUM] CWE-653 CVE-2025-46215: An Improper Isolation or Compartmentalization vulnerability [CWE-653] in Fortinet FortiSandbox 5.0.0 An Improper Isolation or Compartmentalization vulnerability [CWE-653] in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an unauthenticated attacker to evade the sandboxing scan via a crafted file.
cvelistv5nvd
CVE-2024-27779MEDIUMCVSS 6.7≥ 3.2.0, < 4.2.7≥ 4.4.0, < 4.4.5+4 more2025-07-18
CVE-2024-27779 [MEDIUM] CWE-613 CVE-2024-27779: An insufficient session expiration vulnerability [CWE-613] in FortiSandbox FortiSandbox version 4.4. An insufficient session expiration vulnerability [CWE-613] in FortiSandbox FortiSandbox version 4.4.4 and below, version 4.2.6 and below, 4.0 all versions, 3.2 all versions and FortiIsolator version 2.4 and below, 2.3 all versions, 2.2 all versions, 2.1 all versions, 2.0 all versions, 1.2 all versions may allow a remote attacker in possession of an
cvelistv5nvd
CVE-2021-26105HIGHCVSS 8.8≥ 3.1.0, ≤ 3.1.4≥ 3.2.0, < 3.2.3+3 more2025-03-24
CVE-2021-26105 [MEDIUM] CWE-358 CVE-2021-26105: A stack-based buffer overflow vulnerability (CWE-121) in the profile parser of FortiSandbox version A stack-based buffer overflow vulnerability (CWE-121) in the profile parser of FortiSandbox version 3.2.2 and below, version 3.1.4 and below may allow an authenticated attacker to potentially execute unauthorized code or commands via specifically crafted HTTP requests.
cvelistv5nvd
CVE-2024-54027MEDIUMCVSS 4.4≥ 3.0.5, < 4.0.6≥ 4.2.0, < 4.2.8+8 more2025-03-17
CVE-2024-54027 [HIGH] CWE-321 CVE-2024-54027: A Use of Hard-coded Cryptographic Key vulnerability [CWE-321] in FortiSandbox version 4.4.6 and belo A Use of Hard-coded Cryptographic Key vulnerability [CWE-321] in FortiSandbox version 4.4.6 and below, version 4.2.7 and below, version 4.0.5 and below, version 3.2.4 and below, version 3.1.5 and below, version 3.0.7 to 3.0.5 may allow a privileged attacker with super-admin profile and CLI access to read sensitive data via CLI.
cvelistv5nvd
CVE-2024-52960HIGHCVSS 8.8≥ 3.0.0, < 4.2.8≥ 4.4.0, < 4.4.7+7 more2025-03-11
CVE-2024-52960 [MEDIUM] CWE-602 CVE-2024-52960: A client-side enforcement of server-side security vulnerability [CWE-602] in Fortinet FortiSandbox v A client-side enforcement of server-side security vulnerability [CWE-602] in Fortinet FortiSandbox version 5.0.0, 4.4.0 through 4.4.6 and before 4.2.7 allows an authenticated attacker with at least read-only permission to execute unauthorized commands via crafted requests.
cvelistv5nvd
CVE-2024-45328HIGHCVSS 7.8≥ 4.4.0, < 4.4.7≥ 4.4.0, ≤ 4.4.62025-03-11
CVE-2024-45328 [HIGH] CWE-863 CVE-2024-45328: An incorrect authorization vulnerability [CWE-863] in FortiSandbox 4.4.0 through 4.4.6 may allow a l An incorrect authorization vulnerability [CWE-863] in FortiSandbox 4.4.0 through 4.4.6 may allow a low priviledged administrator to execute elevated CLI commands via the GUI console menu.
cvelistv5nvd
CVE-2024-54018HIGHCVSS 7.2≥ 3.2.0, < 4.4.6≥ 4.4.0, ≤ 4.4.4+3 more2025-03-11
CVE-2024-54018 [HIGH] CWE-78 CVE-2024-54018: Multiple improper neutralization of special elements used in an OS Command vulnerabilities [CWE-78] Multiple improper neutralization of special elements used in an OS Command vulnerabilities [CWE-78] in FortiSandbox before 4.4.5 allows a privileged attacker to execute unauthorized commands via crafted requests.
cvelistv5nvd
CVE-2024-52961HIGHCVSS 8.8≥ 3.0.0, < 4.0.6≥ 4.2.0, < 4.2.8+8 more2025-03-11
CVE-2024-52961 [HIGH] CWE-78 CVE-2024-52961: An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerab An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0, FortiSandbox 4.4.0 through 4.4.6, FortiSandbox 4.2.1 through 4.2.7, FortiSandbox 4.0.0 through 4.0.5, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions allows an authenticate
cvelistv5nvd
CVE-2024-54026HIGHCVSS 8.8≥ 3.0.0, < 4.4.7≥ 4.4.0, ≤ 4.4.6+5 more2025-03-11
CVE-2024-54026 [MEDIUM] CWE-89 CVE-2024-54026: An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiSandbox 4.4.0 through 4.4.6, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions, FortiSandbox Cloud 24.1 allows attacker to execute unauthorized
cvelistv5nvd
CVE-2024-27781CRITICALCVSS 9.0≥ 3.0.0, < 4.0.5≥ 4.2.0, < 4.2.7+7 more2025-02-11
CVE-2024-27781 [HIGH] CWE-79 CVE-2024-27781: An improper neutralization of input during web page generation ('cross-site scripting') vulnerabilit An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through 4.0.4, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions allows an authenticated attacker to execute un
cvelistv5nvd
CVE-2024-27778HIGHCVSS 8.8≥ 3.0.5, < 4.0.5≥ 4.2.0, < 4.2.7+7 more2025-01-14
CVE-2024-27778 [HIGH] CWE-78 CVE-2024-27778: An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerab An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through 4.0.4, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0.5 through 3.0.7 allows an authenticated attacker with a
cvelistv5nvd
CVE-2024-31490MEDIUMCVSS 6.5≥ 3.2.2, < 4.2.7≥ 4.4.0, < 4.4.5+5 more2024-09-10
CVE-2024-31490 [MEDIUM] CWE-200 CVE-2024-31490: An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiSandbox An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0 all versions, FortiSandbox 3.2.2 through 3.2.4, FortiSandbox 3.1.5 allows attacker to information disclosure via HTTP get requests.
cvelistv5nvd
CVE-2024-31491HIGHCVSS 8.8≥ 4.2.0, < 4.2.7≥ 4.4.0, < 4.4.5+2 more2024-05-14
CVE-2024-31491 [HIGH] CWE-602 CVE-2024-31491: A client-side enforcement of server-side security vulnerability in Fortinet FortiSandbox 4.4.0 throu A client-side enforcement of server-side security vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6 allows attacker to execute unauthorized code or commands via HTTP requests.
cvelistv5nvd
CVE-2024-23671HIGHCVSS 8.1≥ 4.0.0, < 4.0.5≥ 4.2.0, < 4.2.7+4 more2024-04-09
CVE-2024-23671 [HIGH] CWE-22 CVE-2024-23671: A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fo A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.3, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through 4.0.4 allows attacker to execute unauthorized code or commands via crafted HTTP requests.
cvelistv5nvd