Fortinet Fortiweb vulnerabilities
124 known vulnerabilities affecting fortinet/fortiweb.
Total CVEs
124
CISA KEV
4
actively exploited
Public exploits
5
Exploited in wild
7
Severity breakdown
CRITICAL15HIGH49MEDIUM57LOW3
Vulnerabilities
Page 7 of 7
CVE-2024-36509P4MEDIUMCVSS 4.4≥ 6.3.0, < 7.4.4v7.6.0+4 more2024-11-12
CVE-2024-36509 [MEDIUM] CWE-497 CVE-2024-36509: An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497
An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiWeb version 7.6.0, version 7.4.3 and below, version 7.2.10 and below, version 7.0.10 and below, version 6.3.23 and below may allow an authenticated attacker to access the encrypted passwords of other administrators via the "Log Access Event"
nvd
CVE-2024-55593P4LOWCVSS 2.7≥ 6.3.6, < 7.6.2≥ 7.6.0, ≤ 7.6.1+5 more2025-01-14
CVE-2024-55593 [LOW] CWE-89 CVE-2024-55593: A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet F
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWeb versions 6.3.17 through 7.6.1 allows attacker to gain information disclosure via crafted SQL queries
nvd
CVE-2014-1458P4LOWCVSS 3.5≤ 5.0.32014-02-04
CVE-2014-1458 [LOW] CWE-79 CVE-2014-1458: Cross-site scripting (XSS) vulnerability in the web administration interface in FortiGuard FortiWeb
Cross-site scripting (XSS) vulnerability in the web administration interface in FortiGuard FortiWeb 5.0.3 and earlier allows remote authenticated administrators to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2023-22636P4LOWCVSS 3.3≥ 6.3.6, ≤ 6.3.21≥ 6.4.0, ≤ 6.4.2+1 more2023-02-27
CVE-2023-22636 [LOW] CWE-285 CVE-2023-22636: An unauthorized configuration download vulnerability in FortiWeb 6.3.6 through 6.3.21, 6.4.0 through
An unauthorized configuration download vulnerability in FortiWeb 6.3.6 through 6.3.21, 6.4.0 through 6.4.2 and 7.0.0 through 7.0.4 may allow a local attacker to access confidential configuration files via a crafted http request.
nvd
← Previous7 / 7