Known vulnerabilities in FortiWeb - page 2

Software: FortiWeb
Software CPE: cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
Total vulnerabilities: 89
Public exploits: 9
Known exploited (KEV): 5
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting FortiWeb FortiWeb is affected by 89 known vulnerabilities: 3 critical, 14 high, 31 medium, 41 low Critical High Medium Low

Vulnerabilities (89)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU113971 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-47857
CWE-78 Low
No
No
7.4.9, 7.6.4 12.08.2025 SB20250812106
#VU113968 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-27759
CWE-78 Low
No
No
7.0.11, 7.2.11, 7.4.8, 7.6.4 12.08.2025 SB20250812103
#VU112499 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2025-25257
CWE-89 High
Available
Exploited
7.0.11, 7.2.11, 7.4.8, 7.6.4 08.07.2025 SB2025070847
#VU111054 - Improper Privilege Management
CVE-2025-22254
CWE-269 High
No
No
7.4.7, 7.6.2 11.06.2025 SB2025061119
#VU107250 - Improper Restriction of Communication Channel to Intended Endpoints
CVE-2024-50565
CWE-923 High
No
No
7.4.3 09.04.2025 SB2025040907
SB2025040908
SB2025040909
and 3 more
#VU107249 - Improper Restriction of Communication Channel to Intended Endpoints
CVE-2024-26013
CWE-923 High
No
No
7.4.3 09.04.2025 SB2025040907
SB2025040908
SB2025040909
and 3 more
#VU107246 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-25254
CWE-22 Low
No
No
7.4.7, 7.6.3 09.04.2025 SB2025040904
#VU107210 - Incorrect User Management
CVE-2024-46671
CWE-286 Low
No
No
7.2.11, 7.4.7, 7.6.2 08.04.2025 SB2025040873
#VU105695 - Improper input validation
CVE-2024-55594
CWE-20 Medium
No
No
7.4.7 13.03.2025 SB2025031329
#VU105694 - Improper input validation
CVE-2023-42784
CWE-20 Medium
No
No
7.4.7 13.03.2025 SB2025031329
#VU105622 - Use of Externally-Controlled Format String
CVE-2024-45324
CWE-134 Low
No
No
7.0.11, 7.2.11, 7.4.6, 7.6.1 12.03.2025 SB2025031208
SB2025031209
SB2025031210
and 2 more
#VU105617 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-55597
CWE-22 Low
No
No
7.4.6, 7.6.1 12.03.2025 SB2025031203
#VU103832 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-50569
CWE-78 Low
No
No
7.4.6, 7.6.1 11.02.2025 SB20250211157
#VU103831 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-50567
CWE-78 Low
No
No
7.4.6, 7.6.1 11.02.2025 SB20250211157
#VU103088 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-55593
CWE-89 Low
No
No
7.6.2 21.01.2025 SB2025012103
#VU102875 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-48885
CWE-22 Medium
No
No
7.4.5, 7.6.1 16.01.2025 SB2025011650
SB2025011651
SB2025011652
and 3 more
#VU102874 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-48884
CWE-22 Low
No
No
7.4.5, 7.6.1 16.01.2025 SB2025011650
SB2025011651
SB2025011652
and 3 more
#VU102602 - Stack-based buffer overflow
CVE-2024-21758
CWE-121 Low
No
No
7.2.8, 7.4.2 14.01.2025 SB2025011441
#VU100464 - Exposure of sensitive information to an unauthorized actor
CVE-2024-36509
CWE-200 Low
No
No
7.4.4, 7.6.1 14.11.2024 SB2024111418
#VU93513 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2024-6387
CWE-362 High
Available
No
7.2.10, 7.4.5, 7.6.1 01.07.2024 SB2024070144
SB2024070145
SB2024070152
and 89 more


Showing elements 21 - 40 out of 89