📦 Fortimail

by Fortinet

🔍 What is Fortimail?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-47539

CRITICAL CVSS 9.8 Mar 18, 2025

This vulnerability allows remote unauthenticated attackers to bypass administrator authentication on FortiMail email security appliances. Attackers can gain administrative access by sending specially ...

CVE-2021-36166

CRITICAL CVSS 9.8 Mar 1, 2022

This vulnerability allows remote attackers to efficiently guess administrative authentication tokens in FortiMail systems by observing certain system properties. It affects FortiMail versions before 7...

CVE-2021-24007

CRITICAL CVSS 9.8 Jul 9, 2021

This CVE describes SQL injection vulnerabilities in FortiMail email security appliances that allow unauthenticated attackers to execute arbitrary SQL commands via crafted HTTP requests. Attackers coul...

CVE-2021-26091

HIGH CVSS 7.5 Mar 24, 2025

This vulnerability allows unauthenticated attackers to infer parts of user authentication tokens due to a weak random number generator in FortiMail's Identity Based Encryption service. Attackers could...

CVE-2022-27488

HIGH CVSS 8.3 Dec 13, 2023

This CSRF vulnerability allows remote unauthenticated attackers to trick authenticated administrators into executing malicious CLI commands via crafted GET requests. Affected systems include multiple ...

CVE-2023-36556

HIGH CVSS 8.8 Oct 10, 2023

This CVE describes an incorrect authorization vulnerability in FortiMail webmail that allows authenticated attackers to log into other users' accounts within the same web domain via crafted HTTP/HTTPS...

CVE-2021-32586

HIGH CVSS 7.7 Mar 1, 2022

An unauthenticated attacker can send specially crafted HTTP requests to FortiMail's web server CGI facilities to manipulate the script interpreter's environment. This improper input validation vulnera...

CVE-2021-26095

HIGH CVSS 7.5 Jul 20, 2021

This vulnerability allows remote attackers who have obtained a session cookie to decrypt, modify, or forge its contents, potentially leading to privilege escalation. It affects FortiMail email securit...

CVE-2021-24013

HIGH CVSS 8.8 Jul 12, 2021

This path traversal vulnerability in FortiMail webmail allows authenticated users to access unauthorized files and data through specially crafted web requests. It affects FortiMail systems before vers...

CVE-2021-22129

HIGH CVSS 8.8 Jul 9, 2021

This buffer overflow vulnerability in FortiMail allows authenticated webmail users to execute arbitrary code via crafted HTTP requests. It affects FortiMail versions before 6.4.5, potentially enabling...

CVE-2025-54972

MEDIUM CVSS 4.3 Nov 18, 2025

This CRLF injection vulnerability in Fortinet FortiMail allows attackers to inject HTTP headers into server responses by tricking users into clicking malicious links. Affected systems include FortiMai...

CVE-2023-33302

MEDIUM CVSS 4.7 Mar 31, 2025

This vulnerability allows authenticated attackers with regular webmail access to trigger a buffer overflow via crafted HTTP requests, potentially leading to arbitrary code execution. It affects Fortin...

CVE-2021-24008

MEDIUM CVSS 5.3 Mar 28, 2025

This vulnerability allows remote unauthenticated attackers to obtain sensitive software version information from multiple Fortinet products by reading a JavaScript file. This affects FortiDDoS, FortiD...

CVE-2024-46663

MEDIUM CVSS 6.7 Mar 11, 2025

A stack-buffer overflow vulnerability in Fortinet FortiMail CLI allows privileged attackers to execute arbitrary code or commands via crafted CLI commands. This affects FortiMail versions 7.6.0 throug...

CVE-2022-23439

MEDIUM CVSS 4.7 Jan 22, 2025

This vulnerability allows attackers to poison web caches by sending crafted HTTP requests with malicious Host headers to Fortinet devices. Attackers can redirect users to arbitrary malicious servers, ...

CVE-2024-56497

MEDIUM CVSS 6.7 Jan 14, 2025

This CVE describes an OS command injection vulnerability in Fortinet FortiMail and FortiRecorder products. Attackers with CLI access can execute arbitrary commands on affected systems, potentially lea...