cbcvebase.

Fortinet Fortiweb vulnerabilities

124 known vulnerabilities affecting fortinet/fortiweb.

Total CVEs
124
CISA KEV
4
actively exploited
Public exploits
5
Exploited in wild
7
Severity breakdown
CRITICAL15HIGH49MEDIUM57LOW3

Vulnerabilities

Page 5 of 7
CVE-2020-15942P4MEDIUMCVSS 6.5≥ 6.2.0, ≤ 6.2.3≥ 6.3.0, ≤ 6.3.42021-04-12
CVE-2020-15942 [MEDIUM] CWE-522 CVE-2020-15942: An information disclosure vulnerability in Web Vulnerability Scan profile of Fortinet's FortiWeb ver An information disclosure vulnerability in Web Vulnerability Scan profile of Fortinet's FortiWeb version 6.2.x below 6.2.4 and version 6.3.x below 6.3.5 may allow a remote authenticated attacker to read the password used by the FortiWeb scanner to access the device defined in the scan profile.
nvd
CVE-2024-21758P4MEDIUMCVSS 6.7≥ 7.2.0, < 7.2.8≥ 7.4.0, < 7.4.2+2 more2025-01-14
CVE-2024-21758 [MEDIUM] CWE-121 CVE-2024-21758: A stack-based buffer overflow in Fortinet FortiWeb versions 7.2.0 through 7.2.7, and 7.4.0 through 7 A stack-based buffer overflow in Fortinet FortiWeb versions 7.2.0 through 7.2.7, and 7.4.0 through 7.4.1 may allow a privileged user to execute arbitrary code via specially crafted CLI commands, provided the user is able to evade FortiWeb stack protections.
nvd
CVE-2026-39814P4MEDIUMCVSS 6.7≥ 7.0.10, ≤ 7.0.12≥ 7.2.0, ≤ 7.2.12+5 more2026-04-14
CVE-2026-39814 [MEDIUM] CWE-23 CVE-2026-39814: A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 thr A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.1 through 7.4.12, FortiWeb 7.2.7 through 7.2.12, FortiWeb 7.0.10 through 7.0.12 may allow attacker to execute unauthorized code or commands via
nvd
CVE-2019-16157P4MEDIUMCVSS 6.5≤ 6.2.02020-03-13
CVE-2019-16157 [MEDIUM] CWE-200 CVE-2019-16157: An information exposure vulnerability in Fortinet FortiWeb 6.2.0 CLI and earlier may allow an authen An information exposure vulnerability in Fortinet FortiWeb 6.2.0 CLI and earlier may allow an authenticated user to view sensitive information being logged via diagnose debug commands.
nvd
CVE-2016-5092P4MEDIUMCVSS 4.9≤ 5.5.22016-07-13
CVE-2016-5092 [MEDIUM] CWE-22 CVE-2016-5092: Directory traversal vulnerability in Fortinet FortiWeb before 5.5.3 allows remote authenticated admi Directory traversal vulnerability in Fortinet FortiWeb before 5.5.3 allows remote authenticated administrators with read and write privileges to read arbitrary files by leveraging the autolearn feature.
nvd
CVE-2014-1957P4MEDIUMCVSS 6.5≤ 5.0.22014-04-30
CVE-2014-1957 [MEDIUM] CWE-264 CVE-2014-1957: FortiGuard FortiWeb before 5.0.3 allows remote authenticated users to gain privileges via unspecifie FortiGuard FortiWeb before 5.0.3 allows remote authenticated users to gain privileges via unspecified vectors.
nvd
CVE-2021-32591P4MEDIUMCVSS 5.3≥ 5.7.0, ≤ 5.7.3≥ 5.8.0, ≤ 5.8.7+6 more2021-12-08
CVE-2021-32591 [MEDIUM] CVE-2021-32591: A missing cryptographic steps vulnerability in the function that encrypts users' LDAP and RADIUS cre A missing cryptographic steps vulnerability in the function that encrypts users' LDAP and RADIUS credentials in FortiSandbox before 4.0.1, FortiWeb before 6.3.12, FortiADC before 6.2.1, FortiMail 7.0.1 and earlier may allow an attacker in possession of the password store to compromise the confidentiality of the encrypted secrets.
nvd
CVE-2022-22297P4MEDIUMCVSS 5.5≥ 6.0.0, ≤ 6.0.8≥ 6.1.0, ≤ 6.1.3+3 more2023-03-07
CVE-2022-22297 [MEDIUM] CWE-792 CVE-2022-22297: An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiWeb version 6.4.0 through 6.4.1, FortiWeb version 6.3.0 through 6.3.17, FortiWeb all versions 6.2, FortiWeb all versions 6.1, FortiWeb all versions 6.0, FortiRecorder version 6.4.0 through 6.4.3, FortiRecorder all versi
nvd
CVE-2021-42757P4MEDIUMCVSS 6.7≥ 5.0.0, ≤ 6.3.16v6.4.0+16 more2021-12-08
CVE-2021-42757 [MEDIUM] CWE-120 CVE-2021-42757: A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 thr A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code execution via specially crafted command line arguments.
nvd
CVE-2022-43955P4MEDIUMCVSS 6.1≥ 6.0.0, ≤ 6.2.7≥ 6.3.0, < 6.3.22+6 more2023-04-11
CVE-2022-43955 [MEDIUM] CWE-79 CVE-2022-43955: An improper neutralization of input during web page generation [CWE-79] in the FortiWeb web interfac An improper neutralization of input during web page generation [CWE-79] in the FortiWeb web interface 7.0.0 through 7.0.3, 6.3.0 through 6.3.21, 6.4 all versions, 6.2 all versions, 6.1 all versions and 6.0 all versions may allow an unauthenticated and remote attacker to perform a reflected cross site scripting attack (XSS) via injecting malicious pay
nvd
CVE-2017-14191P4MEDIUMCVSS 5.9≥ 5.6.0, < 6.1.02018-03-20
CVE-2017-14191 [MEDIUM] CVE-2017-14191: An Improper Access Control vulnerability in Fortinet FortiWeb 5.6.0 up to but not including 6.1.0 un An Improper Access Control vulnerability in Fortinet FortiWeb 5.6.0 up to but not including 6.1.0 under "Signed Security Mode", allows attacker to bypass the signed user cookie protection by removing the FortiWeb own protection session cookie.
nvd
CVE-2021-41013P4MEDIUMCVSS 5.3≥ 6.3.0, ≤ 6.3.15v6.4.0+1 more2021-12-08
CVE-2021-41013 [MEDIUM] CWE-863 CVE-2021-41013: An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 a An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Report Browse section of Log & Report may allow an unauthorized and unauthenticated user to access the Log reports via their URLs.
nvd
CVE-2022-42471P4MEDIUMCVSS 5.4≥ 6.3.6, ≤ 6.3.21v6.4.0+7 more2023-01-03
CVE-2022-42471 [MEDIUM] CWE-113 CVE-2022-42471: An improper neutralization of CRLF sequences in HTTP headers ('HTTP Response Splitting') vulnerabili An improper neutralization of CRLF sequences in HTTP headers ('HTTP Response Splitting') vulnerability [CWE-113] In FortiWeb version 7.0.0 through 7.0.2, FortiWeb version 6.4.0 through 6.4.2, FortiWeb version 6.3.6 through 6.3.20 may allow an authenticated and remote attacker to inject arbitrary headers.
nvd
CVE-2025-59669P4MEDIUMCVSS 5.5≥ 7.0.0, < 7.6.1v7.6.0+3 more2025-11-18
CVE-2025-59669 [MEDIUM] CWE-798 CVE-2025-59669: A use of hard-coded credentials vulnerability in Fortinet FortiWeb 7.6.0, FortiWeb 7.4 all versions, A use of hard-coded credentials vulnerability in Fortinet FortiWeb 7.6.0, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow an authenticated attacker with shell access to the device to connect to redis service and access its data
nvd
CVE-2019-16156P4MEDIUMCVSS 6.1≥ 6.0.0, ≤ 6.0.5≥ 6.1.0, ≤ 6.1.1+1 more2020-03-12
CVE-2019-16156 [MEDIUM] CWE-79 CVE-2019-16156: An Improper Neutralization of Input vulnerability in the Anomaly Detection Parameter Name in Fortine An Improper Neutralization of Input vulnerability in the Anomaly Detection Parameter Name in Fortinet FortiWeb 6.0.5, 6.2.0, and 6.1.1 may allow a remote unauthenticated attacker to perform a Cross Site Scripting attack (XSS).
nvd
CVE-2021-43064P4MEDIUMCVSS 6.1≥ 6.2.0, ≤ 6.2.6≥ 6.3.0, ≤ 6.3.15+2 more2021-12-08
CVE-2021-43064 [MEDIUM] CWE-601 CVE-2021-43064: A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and 6.4.0, A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to use the device as a proxy and reach external or protected hosts via redirection handlers.
nvd
CVE-2024-23107P4MEDIUMCVSS 5.5≥ 6.3.0, ≤ 6.3.23≥ 7.0.0, < 7.0.9+4 more2024-06-03
CVE-2024-23107 [MEDIUM] CWE-200 CVE-2024-23107: An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiWeb ve An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiWeb version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, 6.3 all versions may allow an authenticated attacker to read password hashes of other administrators via CLI commands.
nvd
CVE-2014-3115P4MEDIUMCVSS 6.8≤ 5.1.4v5.1.0+3 more2014-05-08
CVE-2014-3115 [MEDIUM] CWE-352 CVE-2014-3115: Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Fort Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Fortinet FortiWeb before 5.2.0 allow remote attackers to hijack the authentication of administrators via system/config/adminadd and other unspecified vectors.
nvd
CVE-2021-43063P4MEDIUMCVSS 6.1≥ 6.2.0, ≤ 6.2.6≥ 6.3.0, ≤ 6.3.15+2 more2021-12-08
CVE-2021-43063 [MEDIUM] CWE-79 CVE-2021-43063: A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet F A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to execute unauthorized code or commands via crafted HTTP GET requests to the login webpage.
nvd
CVE-2021-41015P4MEDIUMCVSS 6.1v6.4.0v6.4.12021-12-08
CVE-2021-41015 [MEDIUM] CWE-79 CVE-2021-41015: A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet F A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests to SAML login handler
nvd
Fortinet Fortiweb vulnerabilities | cvebase