Fortimail

Vendor:

First CVE: Feb 4, 2013 · Active for 13 years

46
Total CVEs
More Total CVEs than 98% of tracked products
5.1
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 43% of tracked products
2.2%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Fortimail over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 4, 2013
13 years ago
Most Recent CVE
May 12, 2026
77 days ago

CVE Severity & Scoring

Fortimail46 CVEs
All CVEs353,173 CVEs
MediumHighCritical
Attack Vector
Local6 (13.0%)
Network37 (80.4%)
Unknown3 (6.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low41 (89.1%)
High2 (4.3%)
Unknown3 (6.5%)
User Interaction
None34 (73.9%)
Unknown3 (6.5%)
Required9 (19.6%)
Privileges Required
Low11 (23.9%)
High10 (21.7%)
None22 (47.8%)
Unknown3 (6.5%)

Top CVEs

Signals from CVEs in this product scope (46 CVEs).

46 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMa
May 13, 20259.885YESNO
An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 and 6.0.1 may allow a remote unauthenticated attacker to acces
Apr 27, 20209.880NOYES
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 and below, version 6.3.7 and bel
Feb 2, 20226.146NOYES
An improper authentication vulnerability in FortiMail before 7.0.1 may allow a remote attacker to efficiently guess one administrative account's authentication token by means of th
Mar 1, 20229.832NONO
An improper input validation vulnerability in the web server CGI facilities of FortiMail before 7.0.1 may allow an unauthenticated attacker to alter the environment of the underlyi
Mar 1, 20229.831NONO
Multiple improper neutralization of special elements of SQL commands vulnerabilities in FortiMail before 6.4.4 may allow a non-authenticated attacker to execute unauthorized code o
Jul 9, 20219.830NONO
An improper access control vulnerability in FortiMail version 7.4.0 configured with RADIUS authentication and remote_wildcard enabled may allow a remote unauthenticated attacker to
Mar 18, 20259.829NONO
A missing cryptographic step in the implementation of the hash digest algorithm in FortiMail 6.4.0 through 6.4.4, and 6.2.0 through 6.2.7 may allow an unauthenticated attacker to t
Jul 9, 20219.829NONO
An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7
May 12, 20267.227NONO
An insufficient verification of data authenticity vulnerability [CWE-345] in FortiClient, FortiMail and FortiOS AV engines version 6.2.168 and below and version 6.4.274 and below m
Nov 2, 20228.627NONO

Exploit Exposure

Signals from CVEs in this product scope (46 CVEs).

CISA KEV
1 CVE
2.2% of CVEs· 98th percentile
Metasploit
1 CVE
2.2% of CVEs· 97th percentile
Nuclei
1 CVE
2.2% of CVEs· 97th percentile
ExploitDB
2 CVEs
4.3% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (46 CVEs).

Media Mentions

Signals from CVEs in this product scope (46 CVEs).

Top CNAs Publishing CVEs For Fortimail

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.4.028.60.8%00
7.2.227.10.6%00
7.2.127.10.6%00
7.2.036.90.5%00
7.0.115.30.9%00
7.0.038.31.1%00
6.4.115.30.8%00
6.4.025.31.3%00
6.2.415.30.8%00
6.2.315.30.8%00
6.2.215.30.8%00
6.2.115.30.8%00
6.2.035.81.0%00
5.3.916.12.1%00
5.3.826.11.6%00
5.3.726.11.6%00
5.3.626.11.6%00
5.3.526.11.6%00
5.3.426.11.6%00
5.3.326.11.6%00