Fortinet Fortiweb vulnerabilities
124 known vulnerabilities affecting fortinet/fortiweb.
Total CVEs
124
CISA KEV
4
actively exploited
Public exploits
5
Exploited in wild
7
Severity breakdown
CRITICAL15HIGH49MEDIUM57LOW3
Vulnerabilities
Page 1 of 7
CVE-2025-64446P1CRITICALCVSS 9.8KEVPoCRansomware≥ 7.0.0, < 7.0.12≥ 7.2.0, < 7.2.12+8 more2025-11-14
CVE-2025-64446 [CRITICAL] CWE-23 CVE-2025-64446: A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 thr
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.
nvd
CVE-2025-25257P1CRITICALCVSS 9.8KEVPoC≥ 7.0.0, < 7.0.11≥ 7.2.0, < 7.2.11+6 more2025-07-17
CVE-2025-25257 [CRITICAL] CWE-89 CVE-2025-25257: An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerabilit
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.7, FortiWeb 7.2.0 through 7.2.10, FortiWeb 7.0.0 through 7.0.10 allows an unauthenticated attacker to execute unauthorized SQL code or commands via crafted
nvd
CVE-2025-58034P1HIGHCVSS 7.2KEVPoC≥ 7.0.0, < 7.0.12≥ 7.2.0, < 7.2.12+7 more2025-11-18
CVE-2025-58034 [HIGH] CWE-78 CVE-2025-58034: An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an authenticated attacker to execute unauthorized
nvd
CVE-2026-24858P1CRITICALCVSS 9.8KEV≥ 7.4.0, ≤ 7.4.11≥ 7.6.0, ≤ 7.6.6+1 more2026-01-27
CVE-2026-24858 [CRITICAL] CWE-288 CVE-2026-24858: An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.
nvd
CVE-2025-52970P1HIGHCVSS 8.1ExploitedPoC≥ 7.0.0, < 7.0.11≥ 7.2.0, < 7.2.11+6 more2025-08-12
CVE-2025-52970 [HIGH] CWE-233 CVE-2025-52970: A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and
A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.0.10 and below may allow an unauthenticated remote attacker with non-public information pertaining to the device and targeted user to gain admin privileges on the device via a specially crafted request.
nvd
CVE-2021-22122P1MEDIUMCVSS 6.1ExploitedPoC≤ 6.2.3≥ 6.3.0, ≤ 6.3.72021-02-08
CVE-2021-22122 [MEDIUM] CWE-79 CVE-2021-22122: An improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 throu
An improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker to perform a reflected cross site scripting attack (XSS) by injecting malicious payload in different vulnerable API end-points.
nvd
CVE-2025-59719P1CRITICALCVSS 9.8Exploited≥ 7.4.0, ≤ 7.4.9≥ 7.6.0, ≤ 7.6.4+1 more2025-12-09
CVE-2025-59719 [CRITICAL] CWE-347 CVE-2025-59719: An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiW
An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.
nvd
CVE-2021-22123P2HIGHCVSS 8.8≥ 5.9.0, < 6.2.4≥ 6.3.0, < 6.3.82021-06-01
CVE-2021-22123 [HIGH] CWE-78 CVE-2021-22123: An OS command injection vulnerability in FortiWeb's management interface 6.3.7 and below, 6.2.3 and
An OS command injection vulnerability in FortiWeb's management interface 6.3.7 and below, 6.2.3 and below, 6.1.x, 6.0.x, 5.9.x may allow a remote authenticated attacker to execute arbitrary commands on the system via the SAML server configuration page.
nvd
CVE-2021-42756P2CRITICALCVSS 9.8≥ 5.6.0, < 6.0.8≥ 6.1.0, < 6.1.3+15 more2023-02-16
CVE-2021-42756 [CRITICAL] CWE-121 CVE-2021-42756: Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x a
Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and below, 6.2.6 and below, 6.3.16 and below, 6.4 all versions may allow an unauthenticated remote attacker to achieve arbitrary code execution via specifically crafted HTTP requests.
nvd
CVE-2023-25610P2CRITICALCVSS 9.8≥ 6.1.0, < 6.1.4≥ 6.2.0, < 6.2.8+10 more2025-03-24
CVE-2023-25610 [CRITICAL] CWE-124 CVE-2023-25610: A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet F
A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.8, version 2.0.12 and below and FortiOS-6K7K version 7.0.5,
nvd
CVE-2024-48884P2CRITICALCVSS 9.1≥ 6.4.0, < 7.4.5v7.6.02025-01-14
CVE-2024-48884 [CRITICAL] CWE-22 CVE-2024-48884: A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fo
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.4, FortiOS 7.2.0 through 7.2.9, FortiOS 7.0.0 through 7.0.15, FortiOS 6.4.0 through 6.4.15, Fo
nvd
CVE-2021-41025P2CRITICALCVSS 9.8≥ 6.0.0, ≤ 6.0.7≥ 6.2.0, ≤ 6.2.6+7 more2021-12-08
CVE-2021-41025 [CRITICAL] CWE-362 CVE-2021-41025: Multiple vulnerabilities in the authentication mechanism of confd in FortiWeb versions 6.4.1, 6.4.0,
Multiple vulnerabilities in the authentication mechanism of confd in FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 thorugh 6.0.7, including an instance of concurrent execution using shared resource with improper synchronization and one of authentication bypass by capture-replay, may allow a r
nvd
CVE-2020-29015P2CRITICALCVSS 9.8fixed in 6.2.4≥ 6.3.0, ≤ 6.3.72021-01-14
CVE-2020-29015 [CRITICAL] CWE-89 CVE-2020-29015: A blind SQL injection in the user interface of FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4
A blind SQL injection in the user interface of FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker to execute arbitrary SQL queries or commands by sending a request with a crafted Authorization header containing a malicious SQL statement.
nvd
CVE-2020-29016P2CRITICALCVSS 9.8fixed in 6.2.4≥ 6.3.0, ≤ 6.3.52021-01-14
CVE-2020-29016 [CRITICAL] CWE-787 CVE-2020-29016: A stack-based buffer overflow vulnerability in FortiWeb 6.3.0 through 6.3.5 and version before 6.2.4
A stack-based buffer overflow vulnerability in FortiWeb 6.3.0 through 6.3.5 and version before 6.2.4 may allow an unauthenticated, remote attacker to overwrite the content of the stack and potentially execute arbitrary code by sending a crafted request with a large certname.
nvd
CVE-2025-64447P2HIGHCVSS 8.1≥ 7.0.0, ≤ 7.0.11≥ 7.2.0, ≤ 7.2.11+3 more2025-12-09
CVE-2025-64447 [HIGH] CWE-565 CVE-2025-64447: A reliance on cookies without validation and integrity checking vulnerability in Fortinet FortiWeb 8
A reliance on cookies without validation and integrity checking vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an unauthenticated attacker to execute arbitrary operations on the system via crafted HTTP or HTTPS r
nvd
CVE-2021-41018P2HIGHCVSS 8.8≥ 6.2.0, < 6.2.7≥ 6.3.0, < 6.3.16+1 more2022-02-02
CVE-2021-41018 [HIGH] CWE-78 CVE-2021-41018: A improper neutralization of special elements used in an os command ('os command injection') in Fort
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests.
nvd
CVE-2022-30303P2HIGHCVSS 8.8≥ 6.3.0, < 6.3.20v6.4.0+7 more2023-02-16
CVE-2022-30303 [HIGH] CWE-78 CVE-2022-30303: An improper neutralization of special elements used in an os command ('OS Command Injection') [CWE-7
An improper neutralization of special elements used in an os command ('OS Command Injection') [CWE-78] in FortiWeb 7.0.0 through 7.0.1, 6.3.0 through 6.3.19, 6.4 all versions may allow an authenticated attacker to execute arbitrary shell code as `root` user via crafted HTTP requests.
nvd
CVE-2022-39951P2HIGHCVSS 8.8≥ 6.3.6, ≤ 6.3.20≥ 6.4.0, ≤ 6.4.2+1 more2023-03-07
CVE-2022-39951 [HIGH] CWE-78 CVE-2022-39951: A improper neutralization of special elements used in an os command ('os command injection') in Fort
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 7.0.0 through 7.0.2, FortiWeb version 6.3.6 through 6.3.20, FortiWeb 6.4 all versions allows attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
nvd
CVE-2021-36182P2HIGHCVSS 8.8≤ 6.2.4≥ 6.3.0, < 6.3.142021-09-08
CVE-2021-36182 [HIGH] CWE-78 CVE-2021-36182: A Improper neutralization of special elements used in a command ('Command Injection') in Fortinet Fo
A Improper neutralization of special elements used in a command ('Command Injection') in Fortinet FortiWeb version 6.3.13 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests
nvd
CVE-2026-24017P2HIGHCVSS 8.1≥ 7.0.0, < 7.0.12≥ 7.2.0, < 7.2.12+8 more2026-03-10
CVE-2026-24017 [HIGH] CWE-799 CVE-2026-24017: An Improper Control of Interaction Frequency vulnerability [CWE-799] vulnerability in Fortinet Forti
An Improper Control of Interaction Frequency vulnerability [CWE-799] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow a remote unauthenticated attacker to bypass the authentication rate-limit via crafted requests.
nvd
1 / 7Next →