Fortinet / FortiSOAR
31 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-22573 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS… | MEDIUM | 6.5 | Apr 14, 2026 |
| CVE-2026-23708 | A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR on-premise 7.6.0 through… | HIGH | 8.1 | Apr 14, 2026 |
| CVE-2025-59809 | A server-side request forgery (ssrf) vulnerability [CWE-918] vulnerability in Fortinet FortiSOAR PaaS 7.6.4, FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS… | MEDIUM | 4.3 | Apr 14, 2026 |
| CVE-2026-22155 | A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR P… | HIGH | 7.5 | Apr 14, 2026 |
| CVE-2026-21742 | A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR P… | MEDIUM | 6.5 | Apr 14, 2026 |
| CVE-2026-22574 | A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.… | MEDIUM | 6.5 | Apr 14, 2026 |
| CVE-2026-22154 | An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR… | MEDIUM | 5.4 | Apr 14, 2026 |
| CVE-2026-22576 | A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.… | MEDIUM | 6.5 | Apr 14, 2026 |
| CVE-2025-59810 | An improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all versions, F… | MEDIUM | 6.5 | Dec 9, 2025 |
| CVE-2025-59808 | An unverified password change vulnerability [CWE-620] vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSO… | MEDIUM | 6.8 | Dec 9, 2025 |
| CVE-2024-48891 | An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR 7.6.0 through 7.6.1, 7.5.0 th… | HIGH | 7.0 | Oct 14, 2025 |
| CVE-2024-48892 | A relative path traversal vulnerability [CWE-23] in FortiSOAR 7.6.0, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all versions may allow an authenticated attacke… | MEDIUM | 6.4 | Aug 12, 2025 |
| CVE-2025-32932 | An Improper neutralization of input during web page generation ('cross-site scripting') vulnerability [CWE-79] in FortiSOAR version 7.6.1 and below, version 7.… | MEDIUM | 6.2 | Aug 12, 2025 |
| CVE-2024-21760 | An improper control of generation of code ('Code Injection') vulnerability [CWE-94] in FortiSOAR Connector FortiSOAR 7.4 all versions, 7.3 all versions, 7.2 al… | HIGH | 8.4 | Mar 18, 2025 |
| CVE-2022-23439 | A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, whe… | MEDIUM | 6.1 | Jan 22, 2025 |
| CVE-2024-47572 | An improper neutralization of formula elements in a csv file in Fortinet FortiSOAR 7.2.1 through 7.4.1 allows attacker to execute unauthorized code or commands… | HIGH | 8.3 | Jan 14, 2025 |
| CVE-2024-48890 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR IMAP connector version 3.5.7… | HIGH | 8.8 | Jan 14, 2025 |
| CVE-2024-36510 | An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, and FortiSOAR 7.5.0, 7.4.0 through 7… | MEDIUM | 5.3 | Jan 14, 2025 |
| CVE-2024-48893 | An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSOAR 7.3.0 through 7.3.3, 7.2.1 through 7.2.2 may allow an authen… | MEDIUM | 6.4 | Jan 14, 2025 |
| CVE-2024-45327 | An improper authorization vulnerability [CWE-285] in FortiSOAR version 7.4.0 through 7.4.3, 7.3.0 through 7.3.2, 7.2.0 through 7.2.2, 7.0.0 through 7.0.3 chang… | HIGH | 7.5 | Sep 11, 2024 |
| CVE-2023-26211 | An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSOAR 7.3.0 through 7.3.2 allows an authenticated, remo… | CRITICAL | 9.0 | Aug 13, 2024 |
| CVE-2023-23775 | Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerabilities [CWE-89] in FortiSOAR 7.2.0 and before 7.0.3 may al… | HIGH | 8.8 | Jun 11, 2024 |
| CVE-2024-31493 | An improper removal of sensitive information before storage or transfer vulnerability [CWE-212] in FortiSOAR version 7.3.0, version 7.2.2 and below, version 7.… | MEDIUM | 6.5 | Jun 3, 2024 |
| CVE-2023-27995 | A improper neutralization of special elements used in a template engine vulnerability in Fortinet FortiSOAR 7.3.0 through 7.3.1 allows an authenticated, remote… | HIGH | 8.8 | Apr 11, 2023 |
| CVE-2023-25605 | A improper access control vulnerability in Fortinet FortiSOAR 7.3.0 - 7.3.1 allows an attacker authenticated on the administrative interface to perform unautho… | HIGH | 7.5 | Mar 7, 2023 |
Showing 1 to 25 of 31 CVEs