Skip to main content

Vendor/product archive

fortinet / fortisoar CVEs

Beta · best-effort

31 CVEs tagged to fortinet / fortisoar1 Critical, 9 High, 20 Medium, 1 Low, 0 Unrated.

CVE-2026-23708

Published Apr 14, 2026

A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-22576

Published Apr 14, 2026

A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, Fort…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-22574

Published Apr 14, 2026

A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, Fort…

CVSS 4.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-22573

Published Apr 14, 2026

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5 all versions, Fo…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-22155

Published Apr 14, 2026

A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-22154

Published Apr 14, 2026

An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through…

CVSS 4.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-21742

Published Apr 14, 2026

A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions…

CVSS 5.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-59809

Published Apr 14, 2026

A server-side request forgery (ssrf) vulnerability [CWE-918] vulnerability in Fortinet FortiSOAR PaaS 7.6.4, FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.2…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59810

Published Dec 9, 2025

An improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 al…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59808

Published Dec 9, 2025

An unverified password change vulnerability [CWE-620] vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all vers…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-48891

Published Oct 14, 2025

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR 7.6.0 through 7.6.1, 7.5.0 through 7.5.1, 7.4 all…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2025-32932

Published Aug 12, 2025

An Improper neutralization of input during web page generation ('cross-site scripting') vulnerability [CWE-79] in FortiSOAR version 7.6.1 and below, version 7.5.1 and below, 7.4 a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-48892

Published Aug 12, 2025

A relative path traversal vulnerability [CWE-23] in FortiSOAR 7.6.0, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all versions may allow an authenticated attacker to read arbitrary…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-21760

Published Mar 18, 2025

An improper control of generation of code ('Code Injection') vulnerability [CWE-94] in FortiSOAR Connector FortiSOAR 7.4 all versions, 7.3 all versions, 7.2 all versions, 7.0 all…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23439

Published Jan 22, 2025

A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` heade…

CVSS 4.7 · Medium

CVE-2024-48893

Published Jan 14, 2025

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSOAR 7.3.0 through 7.3.3, 7.2.1 through 7.2.2 may allow an authenticated attacker to…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47572

Published Jan 14, 2025

An improper neutralization of formula elements in a csv file in Fortinet FortiSOAR 7.2.1 through 7.4.1 allows attacker to execute unauthorized code or commands via manipulating cs…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-45327

Published Sep 11, 2024

An improper authorization vulnerability [CWE-285] in FortiSOAR version 7.4.0 through 7.4.3, 7.3.0 through 7.3.2, 7.2.0 through 7.2.2, 7.0.0 through 7.0.3 change password endpoint…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-26211

Published Aug 13, 2024

An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSOAR 7.3.0 through 7.3.2 allows an authenticated, remote attacker to injec…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23775

Published Jun 11, 2024

Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerabilities [CWE-89] in FortiSOAR 7.2.0 and before 7.0.3 may allow an authenticated…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31493

Published Jun 3, 2024

An improper removal of sensitive information before storage or transfer vulnerability [CWE-212] in FortiSOAR version 7.3.0, version 7.2.2 and below, version 7.0.3 and below may al…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-27995

Published Apr 11, 2023

A improper neutralization of special elements used in a template engine vulnerability in Fortinet FortiSOAR 7.3.0 through 7.3.1 allows an authenticated, remote attacker to execute…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-25605

Published Mar 7, 2023

A improper access control vulnerability in Fortinet FortiSOAR 7.3.0 - 7.3.1 allows an attacker authenticated on the administrative interface to perform unauthorized actions via cr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-38379

Published Dec 6, 2022

Improper neutralization of input during web page generation [CWE-79] in FortiSOAR 7.0.0 through 7.0.3 and 7.2.0 may allow an authenticated attacker to inject HTML tags via input f…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort
Showing 1-25 of 31 CVEsPage 1 of 2