Fortinet / FortiWeb
126 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-26035 | An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through… | CRITICAL | 9.8 | Aug 12, 2026 |
| CVE-2026-70466 | A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions, FortiWe… | MEDIUM | 5.3 | Aug 12, 2026 |
| CVE-2026-40688 | An out-of-bounds write vulnerability [CWE-787] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4… | HIGH | 7.2 | Apr 14, 2026 |
| CVE-2026-39811 | A integer overflow or wraparound vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2… | MEDIUM | 4.9 | Apr 14, 2026 |
| CVE-2026-39814 | A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.1 through 7.4.12, FortiWeb 7.2.7 t… | MEDIUM | 6.7 | Apr 14, 2026 |
| CVE-2025-66178 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7… | HIGH | 7.2 | Mar 10, 2026 |
| CVE-2026-24641 | A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versi… | MEDIUM | 6.5 | Mar 10, 2026 |
| CVE-2026-24640 | A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all ve… | MEDIUM | 6.6 | Mar 10, 2026 |
| CVE-2026-24017 | An Improper Control of Interaction Frequency vulnerability [CWE-799] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, Fort… | HIGH | 8.1 | Mar 10, 2026 |
| CVE-2025-48840 | An authentication bypass by spoofing vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.8, FortiWeb 7.2 all versions, FortiWeb… | MEDIUM | 5.3 | Mar 10, 2026 |
| CVE-2026-30897 | A stack-based buffer overflow vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2… | MEDIUM | 6.6 | Mar 10, 2026 |
| CVE-2026-24858 KEV | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer… | CRITICAL | 9.8 | Jan 27, 2026 |
| CVE-2025-59719 | An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may al… | CRITICAL | 9.8 | Dec 9, 2025 |
| CVE-2025-64471 | A use of password hash instead of password for authentication vulnerability [CWE-836] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 th… | HIGH | 7.5 | Dec 9, 2025 |
| CVE-2025-64447 | A reliance on cookies without validation and integrity checking vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb… | HIGH | 8.1 | Dec 9, 2025 |
| CVE-2025-59669 | A use of hard-coded credentials vulnerability in Fortinet FortiWeb 7.6.0, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may a… | MEDIUM | 5.5 | Nov 18, 2025 |
| CVE-2025-58034 KEV | An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiWeb 8.0.0 t… | HIGH | 7.2 | Nov 18, 2025 |
| CVE-2025-64446 KEV | A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 th… | CRITICAL | 9.8 | Nov 14, 2025 |
| CVE-2024-47569 | A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7.2.0 through 7.2.6, FortiMail 7.0 all v… | MEDIUM | 4.3 | Oct 14, 2025 |
| CVE-2025-53609 | A Relative Path Traversal vulnerability [CWE-23] in FortiWeb 7.6.0 through 7.6.4, 7.4.0 through 7.4.8, 7.2.0 through 7.2.11, 7.0.2 through 7.0.11 may allow an… | MEDIUM | 4.9 | Sep 9, 2025 |
| CVE-2025-47857 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in Fortinet FortiWeb CLI version 7.6.0 thro… | MEDIUM | 6.7 | Aug 12, 2025 |
| CVE-2025-27759 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiWeb version 7.6.0 through… | MEDIUM | 6.7 | Aug 12, 2025 |
| CVE-2025-52970 | A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.0.10 and below may… | HIGH | 8.1 | Aug 12, 2025 |
| CVE-2025-32766 | A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to exe… | MEDIUM | 6.7 | Aug 12, 2025 |
| CVE-2025-25257 KEV | An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through… | CRITICAL | 9.8 | Jul 17, 2025 |
Showing 1 to 25 of 126 CVEs