📦 Fortisandbox

by Fortinet

🔍 What is Fortisandbox?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-53679

HIGH CVSS 7.2 Dec 9, 2025

This OS command injection vulnerability in Fortinet FortiSandbox allows remote privileged attackers to execute arbitrary commands via crafted HTTP/HTTPS requests. Affected systems include FortiSandbox...

CVE-2025-53949

HIGH CVSS 7.2 Dec 9, 2025

This OS command injection vulnerability in Fortinet FortiSandbox allows authenticated attackers to execute arbitrary commands on the underlying system via crafted HTTP requests. Affected users include...

CVE-2024-54027

HIGH CVSS 8.2 Mar 17, 2025

This vulnerability allows a privileged attacker with super-admin profile and CLI access to read sensitive data via hard-coded cryptographic keys in FortiSandbox. It affects multiple versions of FortiS...

CVE-2024-54018

HIGH CVSS 7.2 Mar 11, 2025

This vulnerability allows privileged attackers to execute arbitrary operating system commands on FortiSandbox appliances through crafted requests. It affects FortiSandbox versions before 4.4.5 and req...

CVE-2024-52961

HIGH CVSS 8.8 Mar 11, 2025

This CVE describes an OS command injection vulnerability in Fortinet FortiSandbox that allows authenticated users with read-only permissions to execute arbitrary commands via crafted requests. Attacke...

CVE-2024-45328

HIGH CVSS 7.8 Mar 11, 2025

This vulnerability allows low-privileged administrators in FortiSandbox to execute elevated CLI commands through the GUI console menu due to incorrect authorization checks. It affects FortiSandbox ver...

CVE-2024-27781

HIGH CVSS 7.1 Feb 11, 2025

This is a cross-site scripting (XSS) vulnerability in Fortinet FortiSandbox that allows authenticated attackers to inject malicious scripts into web pages. When exploited, it enables execution of unau...

CVE-2024-27778

HIGH CVSS 8.8 Jan 14, 2025

This CVE-2024-27778 is an OS command injection vulnerability in Fortinet FortiSandbox that allows authenticated attackers with read-only permissions to execute arbitrary commands via crafted requests....

CVE-2024-31491

HIGH CVSS 8.8 May 14, 2024

This vulnerability allows attackers to bypass server-side security controls in Fortinet FortiSandbox by manipulating client-side HTTP requests, enabling unauthorized code or command execution. It affe...

CVE-2024-21756

HIGH CVSS 8.8 Apr 9, 2024

This CVE describes an OS command injection vulnerability in Fortinet FortiSandbox that allows attackers to execute arbitrary commands on affected systems. Attackers can exploit this by sending special...

CVE-2024-23671

HIGH CVSS 8.1 Apr 9, 2024

This path traversal vulnerability in Fortinet FortiSandbox allows attackers to execute arbitrary code or commands via specially crafted HTTP requests. It affects FortiSandbox versions 4.4.0-4.4.3, 4.2...

CVE-2023-41843

HIGH CVSS 7.5 Oct 13, 2023

This cross-site scripting (XSS) vulnerability in Fortinet FortiSandbox allows attackers to inject malicious scripts via crafted HTTP requests, which could lead to unauthorized code execution. Affected...

CVE-2023-41681

HIGH CVSS 7.5 Oct 13, 2023

This is a cross-site scripting (XSS) vulnerability in Fortinet FortiSandbox that allows attackers to inject malicious scripts via crafted HTTP requests. When exploited, it enables execution of unautho...

CVE-2022-27487

HIGH CVSS 8.8 Apr 11, 2023

This vulnerability allows authenticated remote attackers to make unauthorized API calls on Fortinet FortiSandbox and FortiDeceptor systems. Attackers can bypass intended privilege controls via crafted...

CVE-2020-29011

HIGH CVSS 8.8 Aug 4, 2021

This SQL injection vulnerability in FortiSandbox allows authenticated attackers to execute arbitrary SQL commands via crafted HTTP requests to the checksum search and MTA-quarantine modules. Successfu...

CVE-2021-24010

HIGH CVSS 8.1 Aug 4, 2021

This CVE describes a path traversal vulnerability in FortiSandbox that allows authenticated users to access restricted files and directories via specially crafted web requests. The vulnerability affec...

CVE-2025-54353

MEDIUM CVSS 5.4 Dec 9, 2025

This CVE describes a cross-site scripting (XSS) vulnerability in Fortinet FortiSandbox that allows attackers to inject malicious scripts via crafted HTTP requests. The vulnerability affects multiple v...

CVE-2025-46215

MEDIUM CVSS 5.3 Nov 18, 2025

An improper isolation vulnerability in Fortinet FortiSandbox allows unauthenticated attackers to bypass sandbox scanning by submitting specially crafted files. This affects FortiSandbox versions 4.0, ...

CVE-2021-26105

MEDIUM CVSS 6.8 Mar 24, 2025

This CVE describes a stack-based buffer overflow vulnerability in FortiSandbox's profile parser that allows authenticated attackers to execute arbitrary code via crafted HTTP requests. Affected system...

CVE-2024-54026

MEDIUM CVSS 4.3 Mar 11, 2025

This SQL injection vulnerability in Fortinet FortiSandbox allows attackers to execute unauthorized SQL commands via crafted HTTP requests. It affects multiple FortiSandbox versions including 4.4.0-4.4...

CVE-2025-67685

LOW CVSS 3.8 Jan 13, 2026

This SSRF vulnerability in Fortinet FortiSandbox allows authenticated attackers to proxy internal requests to plaintext endpoints via crafted HTTP requests. It affects FortiSandbox versions 4.0, 4.2, ...