cbcvebase.

Fortinet Fortisoar vulnerabilities

32 known vulnerabilities affecting fortinet/fortisoar.

Total CVEs
32
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH14MEDIUM17

Vulnerabilities

Page 2 of 2
CVE-2022-29062P3MEDIUMCVSS 6.5≥ 7.0.0, < 7.0.3v7.2.02022-09-06
CVE-2022-29062 [MEDIUM] CWE-22 CVE-2022-29062: Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiSOAR before 7.2.1 allows Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to write to the underlying filesystem with nginx permissions via crafted HTTP requests.
nvd
CVE-2026-21742P3MEDIUMCVSS 6.5≥ 7.3.0, < 7.5.3≥ 7.6.0, < 7.6.42026-04-14
CVE-2026-21742 [MEDIUM] CWE-319 CVE-2026-21742: A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 thr A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-p
nvd
CVE-2024-31493P3MEDIUMCVSS 6.5≥ 7.0.0, < 7.3.1v7.3.0+2 more2024-06-03
CVE-2024-31493 [MEDIUM] CWE-212 CVE-2024-31493: An improper removal of sensitive information before storage or transfer vulnerability [CWE-212] in F An improper removal of sensitive information before storage or transfer vulnerability [CWE-212] in FortiSOAR version 7.3.0, version 7.2.2 and below, version 7.0.3 and below may allow an authenticated low privileged user to read Connector passwords in plain-text via HTTP responses.
nvd
CVE-2024-36510P4MEDIUMCVSS 5.3≥ 6.4.0, < 7.3.3≥ 7.4.0, < 7.4.5+7 more2025-01-14
CVE-2024-36510 [MEDIUM] CWE-204 CVE-2024-36510: An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7. An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, and FortiSOAR 7.5.0, 7.4.0 through 7.4.4, 7.3.0 through 7.3.2, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to enumerate valid users via observing login request responses.
nvd
CVE-2022-23439P4MEDIUMCVSS 6.1≥ 6.4.0, < 7.3.02025-01-22
CVE-2022-23439 [MEDIUM] CWE-610 CVE-2022-23439: A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver
nvd
CVE-2024-48892P4MEDIUMCVSS 4.9≥ 7.3.0, < 7.5.2v7.6.0+3 more2025-08-12
CVE-2024-48892 [MEDIUM] CWE-23 CVE-2024-48892: A relative path traversal vulnerability [CWE-23] in FortiSOAR 7.6.0, 7.5.0 through 7.5.1, 7.4 all ve A relative path traversal vulnerability [CWE-23] in FortiSOAR 7.6.0, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all versions may allow an authenticated attacker to read arbitrary files via uploading a malicious solution pack.
nvd
CVE-2022-42473P4MEDIUMCVSS 5.5≥ 6.4.0, ≤ 6.4.4≥ 7.0.0, ≤ 7.0.3+1 more2022-11-02
CVE-2022-42473 [MEDIUM] CWE-306 CVE-2022-42473: A missing authentication for a critical function vulnerability in Fortinet FortiSOAR 6.4.0 - 6.4.4 a A missing authentication for a critical function vulnerability in Fortinet FortiSOAR 6.4.0 - 6.4.4 and 7.0.0 - 7.0.3 and 7.2.0 allows an attacker to disclose information via logging into the database using a privileged account without a password.
nvd
CVE-2026-22154P4MEDIUMCVSS 5.4≥ 7.3.0, < 7.5.3≥ 7.6.0, < 7.6.42026-04-14
CVE-2026-22154 [MEDIUM] CWE-79 CVE-2026-22154: An improper neutralization of input during web page generation ('cross-site scripting') vulnerabilit An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-premise 7.5.0 through 7.5.2, FortiSOAR on-pre
nvd
CVE-2025-32932P4MEDIUMCVSS 5.4≥ 6.4.0, < 7.5.2≥ 7.6.0, < 7.6.2+8 more2025-08-12
CVE-2025-32932 [MEDIUM] CWE-79 CVE-2025-32932: An Improper neutralization of input during web page generation ('cross-site scripting') vulnerabilit An Improper neutralization of input during web page generation ('cross-site scripting') vulnerability [CWE-79] in FortiSOAR version 7.6.1 and below, version 7.5.1 and below, 7.4 all versions, 7.3 all versions, 7.2 all versions, 7.0 all versions, 6.4 all versions WEB UI may allow an authenticated remote attacker to perform an XSS attack via stored mal
nvd
CVE-2024-48893P4MEDIUMCVSS 5.4≥ 7.2.1, ≤ 7.3.3≥ 7.3.0, ≤ 7.3.32025-01-14
CVE-2024-48893 [MEDIUM] CWE-79 CVE-2024-48893: An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSOAR 7 An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSOAR 7.3.0 through 7.3.3, 7.2.1 through 7.2.2 may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack via the creation of malicious playbook.
nvd
CVE-2025-59809P4MEDIUMCVSS 4.3≥ 7.3.0, < 7.5.3≥ 7.6.0, < 7.6.3+1 more2026-04-14
CVE-2025-59809 [MEDIUM] CWE-918 CVE-2025-59809: A server-side request forgery (ssrf) vulnerability [CWE-918] vulnerability in Fortinet FortiSOAR Paa A server-side request forgery (ssrf) vulnerability [CWE-918] vulnerability in Fortinet FortiSOAR PaaS 7.6.4, FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.4, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through
nvd
CVE-2022-38379P4MEDIUMCVSS 5.4≥ 7.0.0, ≤ 7.0.3v7.2.02022-12-06
CVE-2022-38379 [MEDIUM] CWE-79 CVE-2022-38379: Improper neutralization of input during web page generation [CWE-79] in FortiSOAR 7.0.0 through 7.0. Improper neutralization of input during web page generation [CWE-79] in FortiSOAR 7.0.0 through 7.0.3 and 7.2.0 may allow an authenticated attacker to inject HTML tags via input fields of various components within FortiSOAR.
nvd
Fortinet Fortisoar vulnerabilities | cvebase