Skip to main content

Vendor/product archive

fortinet / fortimail CVEs

Beta · best-effort

46 CVEs tagged to fortinet / fortimail5 Critical, 12 High, 27 Medium, 2 Low, 0 Unrated.

CVE-2025-53681

Published May 12, 2026

An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-54972

Published Nov 18, 2025

An improper neutralization of crlf sequences ('crlf injection') vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2 all versions,…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47569

Published Oct 14, 2025

A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7.2.0 through 7.2.6, FortiMail 7.0 all versions, FortiManage…

CVSS 4.3 · Medium

CVE-2023-33302

Published Mar 31, 2025

A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiMail webmail and administrative interface version 6.4.0 through 6.4.4 and before 6.2.6 a…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-26091

Published Mar 24, 2025

A use of a cryptographically weak pseudo-random number generator vulnerability in the authenticator of the Identity Based Encryption service of FortiMail 6.4.0 through 6.4.4, and…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-47539

Published Mar 18, 2025

An improper access control vulnerability in FortiMail version 7.4.0 configured with RADIUS authentication and remote_wildcard enabled may allow a remote unauthenticated attacker t…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-46663

Published Mar 11, 2025

A stack-buffer overflow vulnerability [CWE-121] in Fortinet FortiMail CLI version 7.6.0 through 7.6.1 and before 7.4.3 allows a privileged attacker to execute arbitrary code or co…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23439

Published Jan 22, 2025

A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` heade…

CVSS 4.7 · Medium

CVE-2024-56497

Published Jan 14, 2025

An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMail versions 7.2.0 through 7.2.4 and 7.0.0 through 7.0.6 and 6.4.0…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45582

Published Nov 14, 2023

An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiMail webmail version 7.2.0 through 7.2.4, 7.0.0 through 7.0.6 and before 6.4.8 may all…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36633

Published Nov 14, 2023

An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to see and modify the title of…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36637

Published Oct 10, 2023

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiMail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-36556

Published Oct 10, 2023

An incorrect authorization vulnerability [CWE-863] in FortiMail webmail version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.5 and below 6.4.7 allows an authenticated attacker t…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29056

Published Mar 9, 2023

A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiMail version 6.4.0, version 6.2.0 through 6.2.4 and before 6.0.9 allows a rem…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-39945

Published Nov 2, 2022

An improper access control vulnerability [CWE-284] in FortiMail 7.2.0, 7.0.0 through 7.0.3, 6.4 all versions, 6.2 all versions, 6.0 all versions may allow an authenticated admin u…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-26114

Published Sep 6, 2022

An improper neutralization of input during web page generation vulnerability [CWE-79] in the Webmail of FortiMail before 7.2.0 may allow an unauthenticated attacker to trigger a c…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32586

Published Mar 1, 2022

An improper input validation vulnerability in the web server CGI facilities of FortiMail before 7.0.1 may allow an unauthenticated attacker to alter the environment of the underly…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36166

Published Mar 1, 2022

An improper authentication vulnerability in FortiMail before 7.0.1 may allow a remote attacker to efficiently guess one administrative account's authentication token by means of t…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 46 CVEsPage 1 of 2