cbcvebase.

Fortinet Fortiweb vulnerabilities

124 known vulnerabilities affecting fortinet/fortiweb.

Total CVEs
124
CISA KEV
4
actively exploited
Public exploits
5
Exploited in wild
7
Severity breakdown
CRITICAL15HIGH49MEDIUM57LOW3

Vulnerabilities

Page 2 of 7
CVE-2021-42761P2CRITICALCVSS 9.8≥ 5.6.0, < 5.9.2≥ 6.0.0, < 6.0.8+14 more2023-02-16
CVE-2021-42761 [CRITICAL] CWE-384 CVE-2021-42761: A condition for session fixation vulnerability [CWE-384] in the session management of FortiWeb versi A condition for session fixation vulnerability [CWE-384] in the session management of FortiWeb versions 6.4 all versions, 6.3.0 through 6.3.16, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 through 6.0.7, 5.9.0 through 5.9.1 may allow a remote, unauthenticated attacker to infer the session identifier of other users and possibly usurp their sessi
nvd
CVE-2021-43073P2HIGHCVSS 8.8≥ 5.8.0, < 6.2.7≥ 6.3.0, < 6.3.17+1 more2022-02-02
CVE-2021-43073 [HIGH] CWE-78 CVE-2021-43073: A improper neutralization of special elements used in an os command ('os command injection') in Fort A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests.
nvd
CVE-2023-23779P2HIGHCVSS 8.8≥ 6.3.6, ≤ 6.3.19v6.4.0+6 more2023-02-16
CVE-2023-23779 [HIGH] CWE-78 CVE-2023-23779: Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in FortiWeb version 7.0.1 and below, 6.4 all versions, version 6.3.19 and below may allow an authenticated attacker to execute unauthorized code or commands via crafted parameters of HTTP requests.
nvd
CVE-2021-41017P3HIGHCVSS 8.8≥ 6.3.0, ≤ 6.3.15v6.4.0+1 more2021-12-08
CVE-2021-41017 [HIGH] CWE-787 CVE-2021-41017: Multiple heap-based buffer overflow vulnerabilities in some web API controllers of FortiWeb 6.4.1, 6 Multiple heap-based buffer overflow vulnerabilities in some web API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow a remote authenticated attacker to execute arbitrary code or commands via specifically crafted HTTP requests.
nvd
CVE-2021-36186P3CRITICALCVSS 9.8≥ 6.2.0, ≤ 6.2.5≥ 6.3.0, ≤ 6.3.15+1 more2021-11-02
CVE-2021-36186 [CRITICAL] CWE-787 CVE-2021-36186: A stack-based buffer overflow in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6.2.5 an A stack-based buffer overflow in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6.2.5 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests
nvd
CVE-2024-55594P3CRITICALCVSS 9.8≥ 7.0.0, < 7.4.7≥ 7.4.0, ≤ 7.4.6+2 more2025-03-14
CVE-2024-55594 [CRITICAL] CWE-228 CVE-2024-55594: An improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7.4.0 An improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0 through 7.0.10 allows attacker to execute unauthorized code or commands via HTTP/S crafted requests.
nvd
CVE-2023-42784P3CRITICALCVSS 9.8≥ 7.0.0, < 7.4.7≥ 7.4.0, ≤ 7.4.7+2 more2025-03-11
CVE-2023-42784 [CRITICAL] CWE-228 CVE-2023-42784: An improper handling of syntactically invalid structure in Fortinet FortiWeb at least verions 7.4.0 An improper handling of syntactically invalid structure in Fortinet FortiWeb at least verions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0 through 7.0.10 allows attacker to execute unauthorized code or commands via HTTP/S crafted requests.
nvd
CVE-2026-40688P3HIGHCVSS 7.2≥ 7.4.0, < 7.4.12≥ 7.6.0, < 7.6.7+4 more2026-04-14
CVE-2026-40688 [HIGH] CWE-787 CVE-2026-40688: An out-of-bounds write vulnerability [CWE-787] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0. An out-of-bounds write vulnerability [CWE-787] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow a remote privileged attacker to execute arbitrary code or command via crafted HTTP requests.
nvd
CVE-2024-48885P3CRITICALCVSS 9.1≥ 6.4.0, < 7.4.5v7.6.0+4 more2025-01-16
CVE-2024-48885 [CRITICAL] CWE-22 CVE-2024-48885: A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fo A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiRecorder 7.2.0 through 7.2.1, FortiRecorder 7.0.0 through 7.0.4, FortiVoice 7.0.0 through 7.0.4, FortiVoice 6.4.0 through 6.4.9, FortiVoice 6.0 all versions, FortiWeb 7.6.0, FortiWeb 7.4.0 through 7.4.4, FortiWeb 7.2 all versions, FortiWe
nvd
CVE-2025-66178P3HIGHCVSS 7.2≥ 7.0.0, < 7.0.13≥ 7.2.0, < 7.2.13+8 more2026-03-10
CVE-2025-66178 [HIGH] CWE-78 CVE-2025-66178: A improper neutralization of special elements used in an os command ('os command injection') vulnera A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow an authenticated attacked to execute arbitrary commands via a specialy cr
nvd
CVE-2021-36179P3HIGHCVSS 8.8≤ 6.2.4≥ 6.3.0, ≤ 6.3.142021-09-08
CVE-2021-36179 [HIGH] CWE-787 CVE-2021-36179: A stack-based buffer overflow in Fortinet FortiWeb version 6.3.14 and below, 6.2.4 and below allows A stack-based buffer overflow in Fortinet FortiWeb version 6.3.14 and below, 6.2.4 and below allows attacker to execute unauthorized code or commands via crafted parameters in CLI command execution
nvd
CVE-2021-36195P3HIGHCVSS 8.8≥ 6.2.0, ≤ 6.2.5≥ 6.3.0, ≤ 6.3.15+5 more2021-12-08
CVE-2021-36195 [HIGH] CWE-78 CVE-2021-36195: Multiple command injection vulnerabilities in the command line interpreter of FortiWeb versions 6.4. Multiple command injection vulnerabilities in the command line interpreter of FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2.6, and 6.1.0 through 6.1.2 may allow an authenticated attacker to execute arbitrary commands on the underlying system shell via specially crafted command arguments.
nvd
CVE-2021-36194P3HIGHCVSS 8.8≥ 6.3.0, ≤ 6.3.15v6.4.0+1 more2021-12-09
CVE-2021-36194 [HIGH] CWE-787 CVE-2021-36194: Multiple stack-based buffer overflows in the API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 thr Multiple stack-based buffer overflows in the API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow an authenticated attacker to achieve arbitrary code execution via specially crafted requests.
nvd
CVE-2021-43071P3HIGHCVSS 8.8≥ 6.2.0, ≤ 6.2.6≥ 6.3.0, ≤ 6.3.16+2 more2021-12-09
CVE-2021-43071 [HIGH] CWE-787 CVE-2021-43071: A heap-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, A heap-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests to the LogReport API controller.
nvd
CVE-2021-36180P3HIGHCVSS 8.8≥ 5.8.0, ≤ 5.8.6≥ 6.0.0, ≤ 6.0.7+8 more2021-12-08
CVE-2021-36180 [HIGH] CWE-78 CVE-2021-36180: Multiple improper neutralization of special elements used in a command vulnerabilities [CWE-77] in F Multiple improper neutralization of special elements used in a command vulnerabilities [CWE-77] in FortiWeb management interface 6.4.1 and below, 6.3.15 and below, 6.2.5 and below may allow an authenticated attacker to execute unauthorized code or commands via crafted parameters of HTTP requests.
nvd
CVE-2022-30306P3HIGHCVSS 8.8≥ 6.3.6, < 6.3.20v6.4.0+7 more2023-02-16
CVE-2022-30306 [HIGH] CWE-121 CVE-2022-30306: A stack-based buffer overflow vulnerability [CWE-121] in the CA sign functionality of FortiWeb versi A stack-based buffer overflow vulnerability [CWE-121] in the CA sign functionality of FortiWeb version 7.0.1 and below, 6.4 all versions, version 6.3.19 and below may allow an authenticated attacker to achieve arbitrary code execution via specifically crafted password.
nvd
CVE-2023-23780P3HIGHCVSS 8.8≥ 6.3.0, < 6.3.20≥ 6.4.0, ≤ 6.4.2+3 more2023-02-16
CVE-2023-23780 [HIGH] CWE-121 CVE-2023-23780: A stack-based buffer overflow in Fortinet FortiWeb version 7.0.0 through 7.0.1, Fortinet FortiWeb ve A stack-based buffer overflow in Fortinet FortiWeb version 7.0.0 through 7.0.1, Fortinet FortiWeb version 6.3.6 through 6.3.19, Fortinet FortiWeb 6.4 all versions allows attacker to escalation of privilege via specifically crafted HTTP requests.
nvd
CVE-2024-23665P3HIGHCVSS 8.8≥ 6.3.0, ≤ 6.3.23≥ 6.4.0, ≤ 6.4.3+5 more2024-06-03
CVE-2024-23665 [HIGH] CWE-285 CVE-2024-23665: Multiple improper authorization vulnerabilities [CWE-285] in FortiWeb version 7.4.2 and below, versi Multiple improper authorization vulnerabilities [CWE-285] in FortiWeb version 7.4.2 and below, version 7.2.7 and below, version 7.0.10 and below, version 6.4.3 and below, version 6.3.23 and below may allow an authenticated attacker to perform unauthorized ADOM operations via crafted requests.
nvd
CVE-2024-50569P3HIGHCVSS 7.2≥ 7.0.0, < 7.4.6v7.6.0+3 more2025-02-11
CVE-2024-50569 [HIGH] CWE-78 CVE-2024-50569: A improper neutralization of special elements used in an os command ('os command injection') in Fort A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.0.0 through 7.6.0 allows attacker to execute unauthorized code or commands via crafted input.
nvd
CVE-2023-23781P3HIGHCVSS 8.8≥ 6.3.0, < 6.3.20≥ 6.4.0, ≤ 6.4.2+3 more2023-02-16
CVE-2023-23781 [HIGH] CWE-121 CVE-2023-23781: A stack-based buffer overflow vulnerability [CWE-121] in FortiWeb version 7.0.1 and below, 6.4 all v A stack-based buffer overflow vulnerability [CWE-121] in FortiWeb version 7.0.1 and below, 6.4 all versions, version 6.3.19 and below SAML server configuration may allow an authenticated attacker to achieve arbitrary code execution via specifically crafted XML files.
nvd