Fortiweb
Vendor:
First CVE: Feb 4, 2014 · Active for 12 years
124
Total CVEs
More Total CVEs than 99% of tracked products
9.5
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 45% of tracked products
3.2%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Fortiweb over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 4, 2014
12 years ago
Most Recent CVE
Apr 14, 2026
105 days ago
CVE Severity & Scoring
Fortiweb124 CVEs
46%
40%
12%
All CVEs353,173 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local17 (13.7%)
Network99 (79.8%)
Unknown8 (6.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low106 (85.5%)
High10 (8.1%)
Unknown8 (6.5%)
User Interaction
None97 (78.2%)
Unknown8 (6.5%)
Required19 (15.3%)
Privileges Required
Low46 (37.1%)
High28 (22.6%)
None42 (33.9%)
Unknown8 (6.5%)
Top CVEs
Signals from CVEs in this product scope (124 CVEs).
124 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-64446CRITICAL A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWe | Nov 14, 2025 | 9.8 | 99 | YES | YES |
CVE-2025-25257CRITICAL An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4. | Jul 17, 2025 | 9.8 | 98 | YES | YES |
CVE-2026-24858CRITICAL An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, | Jan 27, 2026 | 9.8 | 96 | YES | NO |
CVE-2025-58034HIGH An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWe | Nov 18, 2025 | 7.2 | 93 | YES | YES |
CVE-2021-22123HIGH An OS command injection vulnerability in FortiWeb's management interface 6.3.7 and below, 6.2.3 and below, 6.1.x, 6.0.x, 5.9.x may allow a remote authenticated attacker to execute | Jun 1, 2021 | 8.8 | 71 | NO | NO |
CVE-2025-59719CRITICAL An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticate | Dec 9, 2025 | 9.8 | 52 | NO | NO |
CVE-2021-42756CRITICAL Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and below, 6.2.6 and below, 6.3.16 and below | Feb 16, 2023 | 9.8 | 51 | NO | NO |
CVE-2025-52970HIGH A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.0.10 and below may allow an unauthentica | Aug 12, 2025 | 8.1 | 49 | NO | YES |
CVE-2023-25610CRITICAL A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 t | Mar 24, 2025 | 9.8 | 40 | NO | NO |
CVE-2021-22122MEDIUM An improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker | Feb 8, 2021 | 6.1 | 35 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (124 CVEs).
CISA KEV
4 CVEs
3.2% of CVEs· 98th percentile
Metasploit
2 CVEs
1.6% of CVEs· 97th percentile
Nuclei
4 CVEs
3.2% of CVEs· 97th percentile
ExploitDB
2 CVEs
1.6% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (124 CVEs).
Media Mentions
Signals from CVEs in this product scope (124 CVEs).
Top CNAs Publishing CVEs For Fortiweb
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.0.0 | 1 | 9.8 | 24.1% | 0 | 0 |
| 7.6.0 | 8 | 7.0 | 2.7% | 0 | 0 |
| 7.4.0 | 2 | 5.4 | 0.3% | 0 | 0 |
| 7.2.1 | 1 | 6.5 | 0.8% | 0 | 0 |
| 7.2.0 | 1 | 6.5 | 0.8% | 0 | 0 |
| 7.0.2 | 1 | 5.4 | 0.5% | 0 | 0 |
| 7.0.1 | 9 | 7.1 | 1.0% | 0 | 0 |
| 7.0.0 | 9 | 7.1 | 1.0% | 0 | 0 |
| 6.4.2 | 9 | 7.3 | 1.1% | 0 | 0 |
| 6.4.1 | 23 | 7.3 | 1.0% | 0 | 0 |
| 6.4.0 | 25 | 7.4 | 1.0% | 0 | 0 |
| 6.3.0 | 1 | 5.4 | 0.8% | 0 | 0 |
| 6.2.0 | 1 | 6.1 | 1.0% | 0 | 0 |
| 6.1.2 | 5 | 7.6 | 1.0% | 0 | 0 |
| 6.1.1 | 6 | 7.8 | 1.0% | 0 | 0 |
| 6.1.0 | 6 | 7.8 | 1.0% | 0 | 0 |
| 5.9.1 | 2 | 7.0 | 1.0% | 0 | 0 |
| 5.9.0 | 2 | 7.0 | 1.0% | 0 | 0 |
| 5.8.0 | 1 | 5.4 | 0.3% | 0 | 0 |
| 5.3.4 | 1 | 4.3 | 1.4% | 0 | 0 |