cbcvebase.

Fortinet Fortiweb vulnerabilities

124 known vulnerabilities affecting fortinet/fortiweb.

Total CVEs
124
CISA KEV
4
actively exploited
Public exploits
5
Exploited in wild
7
Severity breakdown
CRITICAL15HIGH49MEDIUM57LOW3

Vulnerabilities

Page 4 of 7
CVE-2021-41014P3HIGHCVSS 7.5≥ 6.0.0, ≤ 6.0.7≥ 6.2.0, ≤ 6.2.5+6 more2021-12-08
CVE-2021-41014 [HIGH] CWE-400 CVE-2021-41014: A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below a A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to make the httpsd daemon unresponsive via huge HTTP packets
nvd
CVE-2023-23783P3HIGHCVSS 7.8≥ 6.4.0, < 6.4.2≥ 7.0.0, < 7.0.2+2 more2023-02-16
CVE-2023-23783 [HIGH] CWE-134 CVE-2023-23783: A use of externally-controlled format string in Fortinet FortiWeb version 7.0.0 through 7.0.1, Forti A use of externally-controlled format string in Fortinet FortiWeb version 7.0.0 through 7.0.1, FortiWeb 6.4 all versions allows attacker to execute unauthorized code or commands via specially crafted command arguments.
nvd
CVE-2023-23782P3HIGHCVSS 7.8≥ 6.0.0, ≤ 6.2.7≥ 6.3.0, < 6.3.20+6 more2023-02-16
CVE-2023-23782 [HIGH] CWE-122 CVE-2023-23782: A heap-based buffer overflow in Fortinet FortiWeb version 7.0.0 through 7.0.1, FortiWeb version 6.3. A heap-based buffer overflow in Fortinet FortiWeb version 7.0.0 through 7.0.1, FortiWeb version 6.3.0 through 6.3.19, FortiWeb 6.4 all versions, FortiWeb 6.2 all versions, FortiWeb 6.1 all versions allows attacker to escalation of privilege via specifically crafted arguments to existing commands.
nvd
CVE-2023-25602P3HIGHCVSS 7.8≥ 5.6.0, < 5.9.2≥ 6.0.0, < 6.0.8+13 more2023-02-16
CVE-2023-25602 [HIGH] CWE-121 CVE-2023-25602: A stack-based buffer overflow in Fortinet FortiWeb 6.4 all versions, FortiWeb versions 6.3.17 and ea A stack-based buffer overflow in Fortinet FortiWeb 6.4 all versions, FortiWeb versions 6.3.17 and earlier, FortiWeb versions 6.2.6 and earlier, FortiWeb versions 6.1.2 and earlier, FortiWeb versions 6.0.7 and earlier, FortiWeb versions 5.9.1 and earlier, FortiWeb 5.8 all versions, FortiWeb 5.7 all versions, FortiWeb 5.6 all versions allows attacker to
nvd
CVE-2025-53609P3MEDIUMCVSS 4.9≥ 7.0.2, < 7.2.12≥ 7.4.0, < 7.4.9+5 more2025-09-09
CVE-2025-53609 [MEDIUM] CWE-23 CVE-2025-53609: A Relative Path Traversal vulnerability [CWE-23] in FortiWeb 7.6.0 through 7.6.4, 7.4.0 through 7.4. A Relative Path Traversal vulnerability [CWE-23] in FortiWeb 7.6.0 through 7.6.4, 7.4.0 through 7.4.8, 7.2.0 through 7.2.11, 7.0.2 through 7.0.11 may allow an authenticated attacker to perform an arbitrary file read on the underlying system via crafted requests.
nvd
CVE-2021-41027P3HIGHCVSS 7.8v6.4.0v6.4.12021-12-08
CVE-2021-41027 [HIGH] CWE-787 CVE-2021-41027: A stack-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, allows an authenticated A stack-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, allows an authenticated attacker to execute unauthorized code or commands via crafted certificates loaded into the device.
nvd
CVE-2021-41026P3MEDIUMCVSS 6.5≥ 6.3.0, < 6.3.16≥ 6.4.0, < 6.4.22022-04-06
CVE-2021-41026 [MEDIUM] CWE-22 CVE-2021-41026: A relative path traversal in FortiWeb versions 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow an a A relative path traversal in FortiWeb versions 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow an authenticated attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests.
nvd
CVE-2025-47857P3MEDIUMCVSS 6.7≥ 7.4.1, < 7.4.9≥ 7.6.0, < 7.6.4+2 more2025-08-12
CVE-2025-47857 [MEDIUM] CWE-78 CVE-2025-47857: A improper neutralization of special elements used in an os command ('os command injection') vulnera A improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to execute arbitrary code or command via crafted CLI commands.
nvd
CVE-2021-36190P3MEDIUMCVSS 6.3≥ 6.0.0, ≤ 6.0.7≥ 6.2.0, ≤ 6.2.6+6 more2021-12-08
CVE-2021-36190 [MEDIUM] CVE-2021-36190: A unintended proxy or intermediary ('confused deputy') in Fortinet FortiWeb version 6.4.1 and below, A unintended proxy or intermediary ('confused deputy') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to access protected hosts via crafted HTTP requests.
nvd
CVE-2025-27759P3MEDIUMCVSS 6.7≥ 7.0.0, < 7.0.11≥ 7.2.0, < 7.2.11+6 more2025-08-12
CVE-2025-27759 [MEDIUM] CWE-78 CVE-2025-27759: An improper neutralization of special elements used in an OS command ('OS Command Injection') vulner An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiWeb version 7.6.0 through 7.6.3, 7.4.0 through 7.4.7, 7.2.0 through 7.2.10 and before 7.0.10 allows an authenticated privileged attacker to execute unauthorized code or commands via crafted CLI commands
nvd
CVE-2016-4066P3HIGHCVSS 8.8≤ 5.5.22016-07-13
CVE-2016-4066 [HIGH] CWE-352 CVE-2016-4066: Cross-site request forgery (CSRF) vulnerability in Fortinet FortiWeb before 5.5.3 allows remote atta Cross-site request forgery (CSRF) vulnerability in Fortinet FortiWeb before 5.5.3 allows remote attackers to hijack the authentication of administrators for requests that change the password via unspecified vectors.
nvd
CVE-2023-23778P3MEDIUMCVSS 6.5≥ 6.2.3, ≤ 6.2.7≥ 6.3.0, ≤ 6.3.21+7 more2023-02-16
CVE-2023-23778 [MEDIUM] CWE-23 CVE-2023-23778: A relative path traversal vulnerability [CWE-23] in FortiWeb version 7.0.1 and below, 6.4 all versio A relative path traversal vulnerability [CWE-23] in FortiWeb version 7.0.1 and below, 6.4 all versions, 6.3 all versions, 6.2 all versions may allow an authenticated user to obtain unauthorized access to files and data via specifically crafted web requests.
nvd
CVE-2025-48840P3MEDIUMCVSS 5.3≥ 7.0.0, < 7.4.9≥ 7.6.0, < 7.6.4+4 more2026-03-10
CVE-2025-48840 [MEDIUM] CWE-290 CVE-2025-48840: An authentication bypass by spoofing vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWe An authentication bypass by spoofing vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.8, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow a remote unauthenticated attacker to bypass hostname restrictions via a specially crafted request.
nvd
CVE-2021-36187P3HIGHCVSS 7.5≥ 6.2.0, ≤ 6.2.5≥ 6.3.0, ≤ 6.3.15+1 more2021-11-02
CVE-2021-36187 [HIGH] CWE-400 CVE-2021-36187: A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6. A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6.2.5 and below allows attacker to cause a denial of service for webserver daemon via crafted HTTP requests
nvd
CVE-2022-30300P3MEDIUMCVSS 6.5≥ 6.3.6, < 6.3.19v6.4.0+7 more2023-02-16
CVE-2022-30300 [MEDIUM] CWE-23 CVE-2022-30300: A relative path traversal vulnerability [CWE-23] in FortiWeb 7.0.0 through 7.0.1, 6.3.6 through 6.3. A relative path traversal vulnerability [CWE-23] in FortiWeb 7.0.0 through 7.0.1, 6.3.6 through 6.3.18, 6.4 all versions may allow an authenticated attacker to obtain unauthorized access to files and data via specifically crafted HTTP GET requests.
nvd
CVE-2026-24641P3MEDIUMCVSS 6.5≥ 7.0.0, < 7.6.7≥ 8.0.0, < 8.0.3+5 more2026-03-10
CVE-2026-24641 [MEDIUM] CWE-476 CVE-2026-24641: A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiWeb 8.0.0 through A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow an authenticated attacker to crash the HTTP daemon via crafted HTTP requests.
nvd
CVE-2023-33305P3MEDIUMCVSS 6.5≥ 6.3.0, ≤ 6.3.23≥ 6.4.0, ≤ 6.4.3+4 more2023-06-13
CVE-2023-33305 [MEDIUM] CWE-835 CVE-2023-33305: A loop with unreachable exit condition ('infinite loop') in Fortinet FortiOS version 7.2.0 through 7 A loop with unreachable exit condition ('infinite loop') in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS version 7.0.0 through 7.0.10, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0 all versions, FortiProxy version 7.2.0 through 7.2.3, FortiProxy version 7.0.0 through 7.0.9, FortiProxy 2.0 all versions, FortiProxy 1.2 all v
nvd
CVE-2025-32766P3MEDIUMCVSS 6.7≥ 7.4.1, < 7.4.9≥ 7.6.0, < 7.6.4+2 more2025-08-12
CVE-2025-32766 [MEDIUM] CWE-121 CVE-2025-32766: A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiWeb CLI version 7.6.0 through A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to execute arbitrary code or commands via crafted CLI commands
nvd
CVE-2023-23784P3MEDIUMCVSS 6.5≥ 6.3.6, < 6.3.21≥ 6.4.0, ≤ 6.4.2+3 more2023-02-16
CVE-2023-23784 [MEDIUM] CWE-23 CVE-2023-23784: A relative path traversal in Fortinet FortiWeb version 7.0.0 through 7.0.2, FortiWeb version 6.3.6 t A relative path traversal in Fortinet FortiWeb version 7.0.0 through 7.0.2, FortiWeb version 6.3.6 through 6.3.20, FortiWeb 6.4 all versions allows attacker to information disclosure via specially crafted web requests.
nvd
CVE-2020-29019P3MEDIUMCVSS 5.3fixed in 6.2.4≥ 6.3.0, ≤ 6.3.72021-01-14
CVE-2020-29019 [MEDIUM] CWE-787 CVE-2020-29019: A stack-based buffer overflow vulnerability in FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4 A stack-based buffer overflow vulnerability in FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4 may allow a remote, unauthenticated attacker to crash the httpd daemon thread by sending a request with a crafted cookie header.
nvd
Fortinet Fortiweb vulnerabilities | cvebase