Fortinet / FortiSandbox
60 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-26084 | A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5,… | CRITICAL | 9.9 | Sep 8, 2026 |
| CVE-2026-84387 | A improper neutralization of special elements used in a command ('command injection') vulnerability in Fortinet FortiSandbox 5.2.0, FortiSandbox 5.0.0 through… | HIGH | 7.2 | Sep 8, 2026 |
| CVE-2026-59835 | A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticate… | HIGH | 8.6 | Jul 14, 2026 |
| CVE-2026-25089 KEV | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiS… | CRITICAL | 9.8 | Jun 9, 2026 |
| CVE-2026-26083 | A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, F… | CRITICAL | 9.8 | May 12, 2026 |
| CVE-2026-39813 | A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of… | CRITICAL | 9.8 | Apr 14, 2026 |
| CVE-2025-61886 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 thr… | MEDIUM | 5.4 | Apr 14, 2026 |
| CVE-2026-39812 | A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox… | MEDIUM | 4.8 | Apr 14, 2026 |
| CVE-2026-25691 | A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0… | MEDIUM | 6.7 | Apr 14, 2026 |
| CVE-2026-27316 | A insufficiently protected credentials vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4 all versions, FortiSandbox PaaS 5.0.1 throu… | LOW | 2.7 | Apr 14, 2026 |
| CVE-2026-39808 KEV | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may all… | CRITICAL | 9.8 | Apr 14, 2026 |
| CVE-2025-53608 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 thr… | MEDIUM | 4.8 | Mar 10, 2026 |
| CVE-2025-52436 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 thr… | CRITICAL | 9.6 | Feb 10, 2026 |
| CVE-2025-67685 | A Server-Side Request Forgery (SSRF) vulnerability [CWE-918] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4, FortiSandbox 4.4 all versions, FortiSa… | LOW | 3.8 | Jan 13, 2026 |
| CVE-2025-53679 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0… | HIGH | 7.2 | Dec 9, 2025 |
| CVE-2025-54353 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 thr… | MEDIUM | 6.1 | Dec 9, 2025 |
| CVE-2025-53949 | An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0… | HIGH | 8.8 | Dec 9, 2025 |
| CVE-2025-46215 | An Improper Isolation or Compartmentalization vulnerability [CWE-653] in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.7, FortiSand… | MEDIUM | 5.3 | Nov 18, 2025 |
| CVE-2024-27779 | An insufficient session expiration vulnerability [CWE-613] in FortiSandbox FortiSandbox version 4.4.4 and below, version 4.2.6 and below, 4.0 all versions, 3.2… | MEDIUM | 6.7 | Jul 18, 2025 |
| CVE-2021-26105 | A stack-based buffer overflow vulnerability (CWE-121) in the profile parser of FortiSandbox version 3.2.2 and below, version 3.1.4 and below may allow an authe… | HIGH | 8.8 | Mar 24, 2025 |
| CVE-2024-54027 | A Use of Hard-coded Cryptographic Key vulnerability [CWE-321] in FortiSandbox version 4.4.6 and below, version 4.2.7 and below, version 4.0.5 and below, versio… | HIGH | 7.8 | Mar 17, 2025 |
| CVE-2024-54026 | An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiSandbox 4.4.0 through 4.4.6, FortiSandbox 4.2 all vers… | HIGH | 8.8 | Mar 11, 2025 |
| CVE-2024-54018 | Multiple improper neutralization of special elements used in an OS Command vulnerabilities [CWE-78] in FortiSandbox before 4.4.5 allows a privileged attacker t… | HIGH | 7.2 | Mar 11, 2025 |
| CVE-2024-52960 | A client-side enforcement of server-side security vulnerability [CWE-602] in Fortinet FortiSandbox version 5.0.0, 4.4.0 through 4.4.6 and before 4.2.7 allows a… | HIGH | 8.8 | Mar 11, 2025 |
| CVE-2024-52961 | An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0, FortiSandbox 4.4.0 th… | HIGH | 8.8 | Mar 11, 2025 |
Showing 1 to 25 of 60 CVEs