FortiSIEM

Fortinet · 32 CVEs

CVE-2026-84389
LOW

A url redirection to untrusted site ('open redirect') vulnerability in Fortinet FortiSIEM 7.5.0 through 7.5.1, FortiSIE…

Sep 8, 2026

CVE-2026-70467
LOW

A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIE…

Aug 12, 2026

CVE-2026-59838
MEDIUM

A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiSIEM 7.4…

Jul 15, 2026

CVE-2026-59841
HIGH

A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7…

Jul 14, 2026

CVE-2026-25972
MEDIUM

An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet Forti…

Mar 10, 2026

CVE-2025-64155
CRITICAL

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet…

Jan 13, 2026

CVE-2025-58324
MEDIUM

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSIEM 7.2.0 through 7.2.2,…

Oct 14, 2025

CVE-2025-25256
CRITICAL

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vu…

Aug 12, 2025

CVE-2023-40714
CRITICAL

A relative path traversal in Fortinet FortiSIEM versions 7.0.0, 6.7.0 through 6.7.2, 6.6.0 through 6.6.3, 6.5.1, 6.5.0…

Apr 2, 2025

CVE-2019-17659
HIGH

A use of hard-coded cryptographic key vulnerability in FortiSIEM version 5.2.6 may allow a remote unauthenticated attac…

Mar 17, 2025

CVE-2024-55592
LOW

An incorrect authorization vulnerability [CWE-863] in FortiSIEM 7.2 all versions, 7.1 all versions, 7.0 all versions, 6…

Mar 11, 2025

CVE-2023-40723
HIGH

An exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.4 and 6.6…

Mar 11, 2025

CVE-2024-27780
MEDIUM

Multiple Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilities [CWE-79]…

Feb 11, 2025

CVE-2024-46667
HIGH

A allocation of resources without limits or throttling in Fortinet FortiSIEM 5.3 all versions, 5.4 all versions, 6.x al…

Jan 14, 2025

CVE-2024-52969
MEDIUM

An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in Forti…

Jan 14, 2025

CVE-2024-23108
CRITICAL

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet…

Feb 5, 2024

CVE-2024-23109
CRITICAL

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet…

Feb 5, 2024

CVE-2023-45585
LOW

An insertion of sensitive information into log file vulnerability [CWE-532] in FortiSIEM version 7.0.0, version 6.7.6 a…

Nov 14, 2023

CVE-2023-41676
MEDIUM

An exposure of sensitive information to an unauthorized actor [CWE-200] in FortiSIEM version 7.0.0 and before 6.7.5 may…

Nov 14, 2023

CVE-2023-36553
CRITICAL

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM vers…

Nov 14, 2023

CVE-2023-34992
CRITICAL

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet…

Oct 10, 2023

CVE-2023-36551
MEDIUM

A exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.5 allows a…

Sep 13, 2023

CVE-2023-26204
CRITICAL

A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all vers…

Jun 13, 2023

CVE-2022-43949
HIGH

A use of a broken or risky cryptographic algorithm [CWE-327] in Fortinet FortiSIEM before 6.7.1 allows a remote unauthe…

Jun 13, 2023

CVE-2022-42478
HIGH

An Improper Restriction of Excessive Authentication Attempts [CWE-307] in FortiSIEM below 7.0.0 may allow a non-privile…

Jun 13, 2023

Showing 1 to 25 of 32 CVEs