cbcvebase.

Fortinet Fortiweb vulnerabilities

124 known vulnerabilities affecting fortinet/fortiweb.

Total CVEs
124
CISA KEV
4
actively exploited
Public exploits
5
Exploited in wild
7
Severity breakdown
CRITICAL15HIGH49MEDIUM57LOW3

Vulnerabilities

Page 6 of 7
CVE-2021-36188P4MEDIUMCVSS 6.1≥ 6.0.0, ≤ 6.2.5≥ 6.3.0, < 6.3.16+1 more2021-12-08
CVE-2021-36188 [MEDIUM] CWE-79 CVE-2021-36188: A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet F A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to execute unauthorized code or commands via crafted GET parameters in requests to login and error handlers
nvd
CVE-2023-46713P4MEDIUMCVSS 5.3≥ 6.2.0, ≤ 6.2.8≥ 6.3.0, ≤ 6.3.23+3 more2023-12-13
CVE-2023-46713 [MEDIUM] CWE-117 CVE-2023-46713: An improper output neutralization for logs in Fortinet FortiWeb 6.2.0 - 6.2.8, 6.3.0 - 6.3.23, 7.0.0 An improper output neutralization for logs in Fortinet FortiWeb 6.2.0 - 6.2.8, 6.3.0 - 6.3.23, 7.0.0 - 7.0.9, 7.2.0 - 7.2.5 and 7.4.0 may allow an attacker to forge traffic logs via a crafted URL of the web application.
nvd
CVE-2024-33509P4MEDIUMCVSS 4.8≥ 6.3.0, < 7.2.2≥ 7.2.0, ≤ 7.2.1+3 more2024-07-09
CVE-2024-33509 [MEDIUM] CWE-295 CVE-2024-33509: An improper certificate validation vulnerability [CWE-295] in FortiWeb 7.2.0 through 7.2.1, 7.0 all An improper certificate validation vulnerability [CWE-295] in FortiWeb 7.2.0 through 7.2.1, 7.0 all versions, 6.4 all versions and 6.3 all versions may allow a remote and unauthenticated attacker in a Man-in-the-Middle position to decipher and/or tamper with the communication channel between the device and different endpoints used to fetch data for W
nvd
CVE-2022-30299P4MEDIUMCVSS 4.3≥ 6.0.0, ≤ 6.0.8≥ 6.1.0, ≤ 6.1.3+10 more2023-02-16
CVE-2022-30299 [MEDIUM] CWE-23 CVE-2022-30299: A path traversal vulnerability [CWE-23] in the API of FortiWeb 7.0.0 through 7.0.1, 6.3.0 through 6. A path traversal vulnerability [CWE-23] in the API of FortiWeb 7.0.0 through 7.0.1, 6.3.0 through 6.3.19, 6.4 all versions, 6.2 all versions, 6.1 all versions, 6.0 all versions may allow an authenticated attacker to retrieve specific parts of files from the underlying file system via specially crafted web requests.
nvd
CVE-2024-47569P4MEDIUMCVSS 4.3≥ 6.4.0, < 7.4.5v7.6.0+4 more2025-10-14
CVE-2024-47569 [MEDIUM] CWE-201 CVE-2024-47569: A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 throug A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7.2.0 through 7.2.6, FortiMail 7.0 all versions, FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiNDR 7.6.0 through 7.6.1, FortiNDR 7.4.0 through 7.4.8, FortiNDR 7.2 al
nvd
CVE-2019-5590P4MEDIUMCVSS 6.1≤ 6.0.2v6.0.2 and below2019-08-28
CVE-2019-5590 [MEDIUM] CWE-79 CVE-2019-5590: The URL part of the report message is not encoded in Fortinet FortiWeb 6.0.2 and below which may all The URL part of the report message is not encoded in Fortinet FortiWeb 6.0.2 and below which may allow an attacker to execute unauthorized code or commands (Cross Site Scripting) via attack reports generated in HTML form.
nvd
CVE-2021-36175P4MEDIUMCVSS 5.4≥ 6.0.0, < 6.2.42021-10-06
CVE-2021-36175 [MEDIUM] CWE-79 CVE-2021-36175: An improper neutralization of input vulnerability [CWE-79] in FortiWebManager versions 6.2.3 and bel An improper neutralization of input vulnerability [CWE-79] in FortiWebManager versions 6.2.3 and below, 6.0.2 and below may allow a remote authenticated attacker to inject malicious script/tags via the name/description/comments parameter of various sections of the device.
nvd
CVE-2014-1956P4MEDIUMCVSS 5.0≤ 5.0.22014-04-30
CVE-2014-1956 [MEDIUM] CVE-2014-1956: CRLF injection vulnerability in FortiGuard FortiWeb before 5.0.3 allows remote attackers to inject a CRLF injection vulnerability in FortiGuard FortiWeb before 5.0.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
nvd
CVE-2026-39811P4MEDIUMCVSS 4.9≥ 7.0.0, ≤ 7.0.13≥ 7.2.0, ≤ 7.2.13+5 more2026-04-14
CVE-2026-39811 [MEDIUM] CWE-190 CVE-2026-39811: A integer overflow or wraparound vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7. A integer overflow or wraparound vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow attacker to denial of service via
nvd
CVE-2012-6346P4MEDIUMCVSS 6.1fixed in 4.4.42018-02-09
CVE-2012-6346 [MEDIUM] CWE-79 CVE-2012-6346: Multiple cross-site scripting (XSS) vulnerabilities in FortiWeb before 4.4.4 allow remote attackers Multiple cross-site scripting (XSS) vulnerabilities in FortiWeb before 4.4.4 allow remote attackers to inject arbitrary web script or HTML via the (1) redir or (2) mkey parameter to waf/pcre_expression/validate.
nvd
CVE-2017-3129P4MEDIUMCVSS 6.1≤ 5.7.12017-05-27
CVE-2017-3129 [MEDIUM] CWE-79 CVE-2017-3129: A Cross-Site Scripting vulnerability in Fortinet FortiWeb versions 5.7.1 and below allows attacker t A Cross-Site Scripting vulnerability in Fortinet FortiWeb versions 5.7.1 and below allows attacker to execute unauthorized code or commands via an improperly sanitized POST parameter in the FortiWeb Site Publisher feature.
nvd
CVE-2020-6646P4MEDIUMCVSS 5.4≤ 6.2.2v6.3.02020-03-17
CVE-2020-6646 [MEDIUM] CWE-79 CVE-2020-6646: An improper neutralization of input vulnerability in FortiWeb allows a remote authenticated attacker An improper neutralization of input vulnerability in FortiWeb allows a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the Disclaimer Description of a Replacement Message.
nvd
CVE-2021-36191P4MEDIUMCVSS 5.4≥ 6.0.0, ≤ 6.0.7≥ 6.2.0, ≤ 6.2.6+6 more2021-12-08
CVE-2021-36191 [MEDIUM] CWE-601 CVE-2021-36191: A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and below, A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to use the device as proxy via crafted GET parameters in requests to error handlers
nvd
CVE-2017-7736P4MEDIUMCVSS 5.4≤ 5.7.1v5.8.02017-11-22
CVE-2017-7736 [MEDIUM] CWE-79 CVE-2017-7736: A stored Cross-site Scripting (XSS) vulnerability in Fortinet FortiWeb webUI Certificate View page i A stored Cross-site Scripting (XSS) vulnerability in Fortinet FortiWeb webUI Certificate View page in 5.8.0, 5.7.1 and earlier, allows attackers to inject arbitrary web script or HTML via special crafted malicious certificate import.
nvd
CVE-2017-7737P4MEDIUMCVSS 4.9≤ 5.8.22017-08-10
CVE-2017-7737 [MEDIUM] CWE-200 CVE-2017-7737: An information disclosure vulnerability in Fortinet FortiWeb 5.8.2 and below versions allows logged- An information disclosure vulnerability in Fortinet FortiWeb 5.8.2 and below versions allows logged-in admin user to view SNMPv3 user password in cleartext in webui via the HTML source code.
nvd
CVE-2021-43074P4MEDIUMCVSS 4.3≥ 6.0.0, < 6.3.17≥ 6.4.0, < 7.0.0+5 more2023-02-16
CVE-2021-43074 [MEDIUM] CWE-347 CVE-2021-43074: An improper verification of cryptographic signature vulnerability [CWE-347] in FortiWeb 6.4 all vers An improper verification of cryptographic signature vulnerability [CWE-347] in FortiWeb 6.4 all versions, 6.3.16 and below, 6.2 all versions, 6.1 all versions, 6.0 all versions; FortiOS 7.0.3 and below, 6.4.8 and below, 6.2 all versions, 6.0 all versions; FortiSwitch 7.0.3 and below, 6.4.10 and below, 6.2 all versions, 6.0 all versions; FortiProxy 7
nvd
CVE-2013-7181P4MEDIUMCVSS 4.3v5.0.32014-02-04
CVE-2013-7181 [MEDIUM] CWE-79 CVE-2013-7181: Cross-site scripting (XSS) vulnerability in user/ldap_user/add in Fortinet FortiOS 5.0.3 allows remo Cross-site scripting (XSS) vulnerability in user/ldap_user/add in Fortinet FortiOS 5.0.3 allows remote attackers to inject arbitrary web script or HTML via the filter parameter.
nvd
CVE-2014-1955P4MEDIUMCVSS 4.3≤ 5.0.22014-04-30
CVE-2014-1955 [MEDIUM] CWE-79 CVE-2014-1955: Cross-site scripting (XSS) vulnerability in FortiGuard FortiWeb before 5.0.3 allows remote attackers Cross-site scripting (XSS) vulnerability in FortiGuard FortiWeb before 5.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2014-8619P4MEDIUMCVSS 4.3v5.1.2v5.1.3+11 more2015-05-12
CVE-2014-8619 [MEDIUM] CWE-79 CVE-2014-8619: Cross-site scripting (XSS) vulnerability in the autolearn configuration page in Fortinet FortiWeb 5. Cross-site scripting (XSS) vulnerability in the autolearn configuration page in Fortinet FortiWeb 5.1.2 through 5.3.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2014-4738P4MEDIUMCVSS 4.3v5.0.0v5.0.2+8 more2014-07-11
CVE-2014-4738 [MEDIUM] CWE-79 CVE-2014-4738: Multiple cross-site scripting (XSS) vulnerabilities in FortiGuard FortiWeb 5.0.x, 5.1.x, and 5.2.x b Multiple cross-site scripting (XSS) vulnerabilities in FortiGuard FortiWeb 5.0.x, 5.1.x, and 5.2.x before 5.2.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) user/ldap_user/check_dlg or (2) user/radius_user/check_dlg.
nvd
Fortinet Fortiweb vulnerabilities | cvebase