Known vulnerabilities in FortiWeb

Software: FortiWeb
Software CPE: cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
Total vulnerabilities: 89
Public exploits: 9
Known exploited (KEV): 5
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting FortiWeb FortiWeb is affected by 89 known vulnerabilities: 3 critical, 14 high, 31 medium, 41 low Critical High Medium Low

Vulnerabilities (89)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU126107 - Out-of-bounds write
CVE-2026-40688
CWE-787 Low
No
No
7.4.12, 7.6.7, 8.0.4 15.04.2026 SB2026041511
#VU125999 - Relative Path Traversal
CVE-2026-39814
CWE-23 Low
No
No
7.6.7, 8.0.3 14.04.2026 SB20260414123
#VU125995 - Integer overflow
CVE-2026-39811
CWE-190 Low
No
No
7.6.7, 8.0.4 14.04.2026 SB20260414118
#VU123728 - Authentication Bypass by Spoofing
CVE-2025-48840
CWE-290 Medium
No
No
7.4.9, 7.6.4 10.03.2026 SB2026031090
#VU123721 - NULL Pointer Dereference
CVE-2026-24641
CWE-476 Low
No
No
7.6.7, 8.0.3 10.03.2026 SB2026031083
#VU123720 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-66178
CWE-78 Low
No
No
7.0.13, 7.2.13, 7.4.12, 7.6.7, 8.0.3 10.03.2026 SB2026031082
#VU123718 - Improper Control of Interaction Frequency
CVE-2026-24017
CWE-799 High
No
No
7.0.12, 7.2.12, 7.4.11, 7.6.6, 8.0.3 10.03.2026 SB2026031080
#VU123705 - Stack-based buffer overflow
CVE-2026-30897
CWE-121 Low
No
No
7.4.12, 7.6.7, 8.0.4 10.03.2026 SB2026031070
#VU123701 - Stack-based buffer overflow
CVE-2026-24640
CWE-121 Low
No
No
7.6.7, 8.0.3 10.03.2026 SB2026031067
#VU119696 - Improper Verification of Cryptographic Signature
CVE-2025-59719
CWE-347 Critical
Available
Exploited
7.4.10, 7.6.5, 8.0.1 10.12.2025 SB2025121064
#VU119694 - Improper Verification of Cryptographic Signature
CVE-2025-59718
CWE-347 Critical
Available
Exploited
7.4.10, 7.6.5, 8.0.1 10.12.2025 SB2025121064
#VU119441 - Reliance on Cookies without Validation and Integrity Checking
CVE-2025-64447
CWE-565 High
No
No
7.0.12, 7.2.12, 7.4.11, 7.6.6, 8.0.2 09.12.2025 SB2025120952
#VU119440 - Use of Password Hash Instead of Password for Authentication
CVE-2025-64471
CWE-836 Low
No
No
7.0.12, 7.2.12, 7.4.11, 7.6.6, 8.0.2 09.12.2025 SB2025120951
#VU118603 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-58034
CWE-78 High
Available
Exploited
7.0.12, 7.2.12, 7.4.11, 7.6.6, 8.0.2 18.11.2025 SB2025111872
#VU118595 - Use of Hard-coded Credentials
CVE-2025-59669
CWE-798 Low
No
No
7.6.1 18.11.2025 SB2025111864
#VU118555 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-64446
CWE-22 Critical
Available
Exploited
7.0.12, 7.2.12, 7.4.10, 7.6.5, 8.0.2 14.11.2025 SB20251114107
#VU117148 - Insertion of Sensitive Information Into Sent Data
CVE-2024-47569
CWE-201 Low
No
No
7.4.5, 7.6.1 15.10.2025 SB2025101507
#VU115082 - Relative Path Traversal
CVE-2025-53609
CWE-23 Low
No
No
7.2.12, 7.4.9, 7.6.5 09.09.2025 SB2025090983
#VU113973 - Improper Handling of Parameters
CVE-2025-52970
CWE-233 High
Available
No
7.0.11, 7.2.11, 7.4.8, 7.6.4 12.08.2025 SB20250812108
#VU113972 - Stack-based buffer overflow
CVE-2025-32766
CWE-121 Low
No
No
7.4.9, 7.6.4 12.08.2025 SB20250812107


Showing elements 1 - 20 out of 89