Skip to main content

Vendor/product archive

fortinet / fortiportal CVEs

Beta · best-effort

45 CVEs tagged to fortinet / fortiportal4 Critical, 9 High, 29 Medium, 3 Low, 0 Unrated.

CVE-2026-49938

Published Jun 9, 2026

A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2.0 through 7.2.8, FortiPortal 7.0 all versions may allow attacker to improper a…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-54838

Published Dec 9, 2025

An Incorrect Authorization vulnerability [CWE-863] in FortiPortal 7.4.0 through 7.4.5 may allow an authenticated attacker to reboot a shared FortiGate device via crafted HTTP requ…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45329

Published Jun 10, 2025

A authorization bypass through user-controlled key in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5, and versions 7.0.0 through 7.0.8 may allow an authenticate…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-46777

Published May 28, 2025

A insertion of sensitive information into log file in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5, and versions 7.0.0 through 7.0.9 may allow an authenticate…

CVSS 2.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-40590

Published Mar 14, 2025

An improper certificate validation vulnerability [CWE-295] in FortiPortal version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, version 6.0.15 and below when connecting…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24470

Published Feb 11, 2025

An Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.11 may allow a remote unauthenticated…

CVSS 8.6 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-52967

Published Jan 14, 2025

An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiPortal 6.0.0 through 6.0.14 allows attacker to execute unauthorized code or comma…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-35278

Published Jan 14, 2025

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.2.4 through 7.2.0 and 7.0.0 through 7.2.8 may allow an au…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-47543

Published Nov 12, 2024

An authorization bypass through user-controlled key vulnerability [CWE-639] in Fortinet FortiPortal version 7.0.0 through 7.0.3 allows an authenticated attacker to interact with r…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-21759

Published Jul 9, 2024

An authorization bypass through user-controlled key in Fortinet FortiPortal version 7.2.0, and versions 7.0.0 through 7.0.6 allows attacker to view unauthorized resources via HTTP…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31495

Published Jun 11, 2024

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.0.0 through 7.0.6 and version 7.2.0 allows privileged use…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48789

Published Jun 3, 2024

A client-side enforcement of server-side security in Fortinet FortiPortal version 6.0.0 through 6.0.14 allows attacker to improper access control via crafted HTTP requests.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23105

Published May 14, 2024

A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2.0 through 7.2.1 allows an unauthenticated attack to bypass…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-21761

Published Mar 12, 2024

An improper authorization vulnerability [CWE-285] in FortiPortal version 7.2.0, and versions 7.0.6 and below reports may allow a user to download other organizations reports via m…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48783

Published Jan 10, 2024

An Authorization Bypass Through User-Controlled Key vulnerability [CWE-639] affecting PortiPortal version 7.2.1 and below, version 7.0.6 and below, version 6.0.14 and below, versi…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46712

Published Jan 10, 2024

A improper access control in Fortinet FortiPortal version 7.0.0 through 7.0.6, Fortinet FortiPortal version 7.2.0 through 7.2.1 allows attacker to escalate its privilege via speci…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-48791

Published Dec 13, 2023

An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in FortiPortal version 7.2.0, version 7.0.6 and below may allow a rem…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-43954

Published Feb 16, 2023

An insertion of sensitive information into log file vulnerability [CWE-532] in the FortiPortal management interface 7.0.0 through 7.0.2 may allow a remote authenticated attacker t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-41336

Published Jan 3, 2023

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiPortal versions 6.0.0 through 6.0.11 and all versions of 5.3, 5.2, 5.1, 5.0 managemen…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 45 CVEsPage 1 of 2