📦 Fortiweb

by Fortinet

🔍 What is Fortiweb?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-24858

CRITICAL CVSS 9.8 Jan 27, 2026

This authentication bypass vulnerability allows attackers with a FortiCloud account and registered device to log into other organizations' Fortinet devices when FortiCloud SSO authentication is enable...

CVE-2025-64446

CRITICAL CVSS 9.8 Nov 14, 2025

A relative path traversal vulnerability in Fortinet FortiWeb web application firewalls allows attackers to execute administrative commands via crafted HTTP/HTTPS requests. This affects FortiWeb versio...

CVE-2025-25257

CRITICAL CVSS 9.8 Jul 17, 2025

This SQL injection vulnerability in Fortinet FortiWeb web application firewalls allows unauthenticated attackers to execute arbitrary SQL commands via crafted HTTP/HTTPS requests. Affected organizatio...

CVE-2023-25610

CRITICAL CVSS 9.8 Mar 24, 2025

This critical vulnerability allows remote unauthenticated attackers to execute arbitrary code or commands on affected Fortinet devices via crafted requests to the administrative interface. It affects ...

CVE-2021-42756

CRITICAL CVSS 9.8 Feb 16, 2023

This critical vulnerability allows unauthenticated remote attackers to execute arbitrary code on FortiWeb web application firewalls via specially crafted HTTP requests. It affects multiple FortiWeb ve...

CVE-2020-29015

CRITICAL CVSS 9.8 Jan 14, 2021

This CVE describes a blind SQL injection vulnerability in FortiWeb's user interface that allows unauthenticated remote attackers to execute arbitrary SQL queries or commands. Attackers can exploit thi...

CVE-2025-64447

HIGH CVSS 8.1 Dec 9, 2025

This vulnerability allows unauthenticated attackers to execute arbitrary operations on FortiWeb web application firewalls by sending crafted HTTP/HTTPS requests with forged cookies. Attackers need pri...

CVE-2025-58034

HIGH CVSS 7.2 Nov 18, 2025

This OS command injection vulnerability in Fortinet FortiWeb web application firewalls allows authenticated attackers to execute arbitrary commands on the underlying system. Attackers can exploit this...

CVE-2024-45324

HIGH CVSS 7.2 Mar 11, 2025

A format string vulnerability in multiple Fortinet products allows privileged attackers to execute arbitrary code via crafted HTTP/HTTPS requests. This affects FortiOS, FortiProxy, FortiPAM, FortiSRA,...

CVE-2024-50567

HIGH CVSS 7.2 Feb 11, 2025

This CVE describes an OS command injection vulnerability in Fortinet FortiWeb web application firewalls. Attackers can execute arbitrary commands on affected devices by sending specially crafted input...

CVE-2023-23777

HIGH CVSS 7.2 Jul 11, 2023

This vulnerability allows privileged attackers to execute arbitrary bash commands on FortiWeb web application firewalls through crafted CLI backup parameters. It affects FortiWeb versions 7.0.1 and be...

CVE-2022-43955

HIGH CVSS 8.8 Apr 11, 2023

This vulnerability allows unauthenticated remote attackers to perform reflected cross-site scripting (XSS) attacks against FortiWeb web interfaces by injecting malicious payloads into log entries used...

CVE-2022-39951

HIGH CVSS 7.2 Mar 7, 2023

This CVE describes an OS command injection vulnerability in Fortinet FortiWeb web application firewalls. Attackers can execute arbitrary commands on affected devices by sending specially crafted HTTP ...

CVE-2023-23780

HIGH CVSS 8.0 Feb 16, 2023

This CVE describes a stack-based buffer overflow vulnerability in Fortinet FortiWeb web application firewalls. Attackers can exploit it via specially crafted HTTP requests to escalate privileges, pote...

CVE-2023-23782

HIGH CVSS 7.8 Feb 16, 2023

This is a heap-based buffer overflow vulnerability in Fortinet FortiWeb web application firewalls that allows attackers to escalate privileges by sending specially crafted arguments to existing comman...

CVE-2023-25602

HIGH CVSS 7.8 Feb 16, 2023

This CVE describes a stack-based buffer overflow vulnerability in Fortinet FortiWeb web application firewalls. Attackers can exploit it by sending specially crafted command arguments to execute arbitr...

CVE-2022-40683

HIGH CVSS 7.8 Feb 16, 2023

CVE-2022-40683 is a double-free vulnerability in Fortinet FortiWeb web application firewalls that could allow attackers to execute arbitrary code or commands. This affects FortiWeb versions 7.0.0 thro...

CVE-2022-30303

HIGH CVSS 8.8 Feb 16, 2023

This vulnerability allows authenticated attackers to execute arbitrary shell commands with root privileges on FortiWeb web application firewalls. It affects FortiWeb versions 6.3.0-6.3.19, 6.4 all ver...

CVE-2021-43073

HIGH CVSS 8.8 Feb 2, 2022

This OS command injection vulnerability in Fortinet FortiWeb allows attackers to execute arbitrary commands on affected devices via specially crafted HTTP requests. It affects FortiWeb versions 6.4.1 ...

CVE-2021-43071

HIGH CVSS 8.8 Dec 9, 2021

This vulnerability allows remote attackers to execute arbitrary code on Fortinet FortiWeb web application firewalls via specially crafted HTTP requests to the LogReport API controller. Attackers can e...

CVE-2021-36194

HIGH CVSS 8.8 Dec 9, 2021

This vulnerability allows authenticated attackers to execute arbitrary code on FortiWeb web application firewalls through stack-based buffer overflows in API controllers. Attackers can gain full syste...

CVE-2021-41017

HIGH CVSS 8.8 Dec 8, 2021

This vulnerability allows remote authenticated attackers to execute arbitrary code or commands on affected FortiWeb devices via crafted HTTP requests. It affects FortiWeb versions 6.3.0 through 6.3.15...

CVE-2021-41014

HIGH CVSS 7.5 Dec 8, 2021

CVE-2021-41014 is a denial-of-service vulnerability in Fortinet FortiWeb web application firewalls where unauthenticated attackers can send specially crafted huge HTTP packets to crash the httpsd daem...

CVE-2021-36180

HIGH CVSS 8.1 Dec 8, 2021

This vulnerability allows authenticated attackers to execute arbitrary commands on FortiWeb web application firewalls by sending specially crafted HTTP requests to the management interface. It affects...

CVE-2021-36182

HIGH CVSS 8.8 Sep 8, 2021

This vulnerability allows attackers to execute arbitrary commands on Fortinet FortiWeb web application firewalls by sending specially crafted HTTP requests. It affects FortiWeb version 6.3.13 and belo...

CVE-2021-22123

HIGH CVSS 7.6 Jun 1, 2021

This CVE describes an OS command injection vulnerability in FortiWeb's management interface that allows remote authenticated attackers to execute arbitrary commands on the system. The vulnerability ex...

CVE-2025-64471

MEDIUM CVSS 4.9 Dec 9, 2025

This vulnerability allows unauthenticated attackers to bypass authentication on FortiWeb web application firewalls by using password hashes instead of actual passwords. Attackers can craft HTTP/HTTPS ...

CVE-2025-59669

MEDIUM CVSS 5.3 Nov 18, 2025

This vulnerability involves hard-coded credentials in Fortinet FortiWeb web application firewalls that could allow authenticated attackers with shell access to connect to the Redis service and access ...

CVE-2025-53609

MEDIUM CVSS 4.9 Sep 9, 2025

A relative path traversal vulnerability in FortiWeb web application firewalls allows authenticated attackers to read arbitrary files on the underlying system. This affects FortiWeb versions 7.6.0-7.6....

CVE-2025-32766

MEDIUM CVSS 6.4 Aug 12, 2025

A stack-based buffer overflow vulnerability in Fortinet FortiWeb CLI allows privileged attackers to execute arbitrary code or commands via crafted CLI commands. This affects FortiWeb versions 7.6.0 th...

CVE-2025-47857

MEDIUM CVSS 6.7 Aug 12, 2025

This CVE describes an OS command injection vulnerability in Fortinet FortiWeb's command-line interface that allows privileged attackers to execute arbitrary commands. Affected systems include FortiWeb...

CVE-2025-22254

MEDIUM CVSS 6.6 Jun 10, 2025

This CVE describes an improper privilege management vulnerability in multiple Fortinet products where authenticated users with read-only admin permissions can escalate to super-admin privileges via cr...

CVE-2024-46671

MEDIUM CVSS 6.2 Apr 8, 2025

This vulnerability allows authenticated attackers with read-only admin permissions in FortiWeb to manipulate other administrators' dashboard widgets via specially crafted requests. It affects FortiWeb...

CVE-2024-55594

MEDIUM CVSS 5.6 Mar 14, 2025

CVE-2024-55594 is an improper input validation vulnerability in Fortinet FortiWeb web application firewalls that allows attackers to execute arbitrary code or commands via specially crafted HTTP/S req...

CVE-2024-55597

MEDIUM CVSS 5.5 Mar 11, 2025

This path traversal vulnerability in Fortinet FortiWeb web application firewalls allows attackers to bypass directory restrictions and potentially execute unauthorized code or commands. It affects org...

CVE-2023-42784

MEDIUM CVSS 5.6 Mar 11, 2025

CVE-2023-42784 is an improper input validation vulnerability in Fortinet FortiWeb web application firewalls that allows attackers to execute arbitrary code or commands via specially crafted HTTP/S req...

CVE-2024-50569

MEDIUM CVSS 6.6 Feb 11, 2025

This OS command injection vulnerability in Fortinet FortiWeb allows attackers to execute arbitrary commands on affected devices by sending specially crafted input. It affects FortiWeb versions 7.0.0 t...

CVE-2024-48885

MEDIUM CVSS 5.3 Jan 16, 2025

This path traversal vulnerability (CWE-22) in multiple Fortinet products allows attackers to escalate privileges by sending specially crafted packets. Affected systems include FortiRecorder, FortiVoic...

CVE-2024-21758

MEDIUM CVSS 6.4 Jan 14, 2025

A stack-based buffer overflow vulnerability in Fortinet FortiWeb allows privileged users to execute arbitrary code via specially crafted CLI commands. This affects FortiWeb versions 7.2.0-7.2.7 and 7....

CVE-2024-33509

MEDIUM CVSS 4.8 Jul 9, 2024

This vulnerability allows a man-in-the-middle attacker to intercept and manipulate communications between FortiWeb WAF devices and external data sources. Attackers could decrypt or tamper with data fe...

CVE-2024-23107

MEDIUM CVSS 5.5 Jun 3, 2024

This vulnerability allows authenticated attackers on FortiWeb web application firewalls to read password hashes of other administrators through CLI commands. This affects FortiWeb versions 7.4.0, 7.2....