Known vulnerabilities in FortiSIEM

Software: FortiSIEM
Software CPE: cpe:2.3:a:fortinet:fortisiem:*:*:*:*:*:*:*:*
Total vulnerabilities: 33
Public exploits: 6
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting FortiSIEM FortiSIEM is affected by 33 known vulnerabilities: 3 critical, 8 high, 5 medium, 17 low Critical High Medium Low

Vulnerabilities (33)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU142455 - Server-Side Request Forgery (SSRF)
CVE-2026-70467
CWE-918 Low
No
No
7.3.6, 7.4.3, 7.5.1 13.08.2026 SB2026081399
#VU137526 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-59838
CWE-79 Low
No
No
7.2.7, 7.3.5, 7.4.1 14.07.2026 SB2026071493
#VU123706 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-25972
CWE-79 Low
No
No
7.3.5, 7.4.1 10.03.2026 SB2026031071
#VU121224 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-64155
CWE-78 Critical
Available
No
7.1.9, 7.2.7, 7.3.5, 7.4.1 13.01.2026 SB2026011363
#VU117205 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2025-58324
CWE-79 Low
No
No
7.2.3 15.10.2025 SB2025101563
#VU113969 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-25256
CWE-78 Critical
Available
Exploited
6.7.10, 7.0.4, 7.1.8, 7.2.6, 7.3.2 12.08.2025 SB20250812104
#VU105620 - Incorrect Authorization
CVE-2024-55592
CWE-863 Low
No
No
7.3.0 12.03.2025 SB2025031206
#VU105609 - Exposure of sensitive information to an unauthorized actor
CVE-2023-40723
CWE-200 High
No
No
6.4.3, 6.5.2, 6.6.4, 6.7.5 11.03.2025 SB20250311111
#VU103883 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-27780
CWE-79 Low
No
No
7.2.0 12.02.2025 SB2025021203
#VU102705 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-52969
CWE-89 Low
No
No
7.2.0 14.01.2025 SB2025011476
#VU102703 - Allocation of Resources Without Limits or Throttling
CVE-2024-46667
CWE-770 Medium
No
No
7.1.6 14.01.2025 SB2025011475
#VU84861 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2022-43949
CWE-327 Medium
No
No
6.7.2 29.12.2023 SB2023061233
#VU83251 - Information Exposure Through Log Files
CVE-2023-45585
CWE-532 Low
No
No
6.4.3, 6.5.2, 6.6.4, 6.7.7, 7.0.1, 7.1.0 17.11.2023 SB2023111735
#VU83250 - Information Exposure Through Log Files
CVE-2023-41676
CWE-532 Medium
No
No
6.7.6, 7.0.1, 7.1.0 17.11.2023 SB2023111736
#VU83249 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-36553
CWE-78 High
No
No
6.4.3, 6.5.2, 6.6.4, 6.7.6, 7.0.1, 7.1.0 17.11.2023 SB2023111736
#VU81967 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-34992
CWE-78 High
Available
No
6.4.4, 6.5.3, 6.6.5, 6.7.9, 7.0.3, 7.1.2 12.10.2023 SB2023101278
#VU86212 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-23108
CWE-78 High
Available
No
6.4.4, 6.5.3, 6.6.5, 6.7.9, 7.0.3, 7.1.2 12.10.2023 SB2023101278
#VU86213 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-23109
CWE-78 High
No
No
6.4.4, 6.5.3, 6.6.5, 6.7.9, 7.0.3, 7.1.2 12.10.2023 SB2023101278
#VU81929 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-40714
CWE-22 Medium
No
No
6.4.3, 6.5.2, 6.6.4, 6.7.4, 7.0.1 11.10.2023 SB2023101196
#VU80869 - Exposure of sensitive information to an unauthorized actor
CVE-2023-36551
CWE-200 Low
No
No
6.7.6 18.09.2023 SB2023091833


Showing elements 1 - 20 out of 33