Known Vulnerabilities for FortiSandbox by Fortinet
Listed below are 10 of the newest known vulnerabilities associated with "FortiSandbox" by "Fortinet".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-39813 json | A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 m... | Not Provided | 2026-04-14 | 2026-04-15 |
| CVE-2026-39812 json | A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox... | Not Provided | 2026-04-14 | 2026-04-14 |
| CVE-2026-39808 json | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiS... | Not Provided | 2026-04-14 | 2026-04-22 |
| CVE-2026-27316 json | A insufficiently protected credentials vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4 all versi... | Not Provided | 2026-04-14 | 2026-04-14 |
| CVE-2026-25691 json | A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 5.0.0... | Not Provided | 2026-04-14 | 2026-04-14 |
| CVE-2025-61886 json | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability ... | Not Provided | 2026-04-14 | 2026-04-14 |
| CVE-2023-41843 json | A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSandbox version 4.4.1... | 5.4 - MEDIUM | 2023-10-13 | 2023-11-07 |
| CVE-2023-41836 json | An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSandbox version 4.4.... | 6.1 - MEDIUM | 2023-10-13 | 2023-11-07 |
| CVE-2023-41682 json | A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiSandbox version 4.4.0 and 4... | 7.5 - HIGH | 2023-10-13 | 2023-11-07 |
| CVE-2023-41681 json | A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSandbox version 4.4.1... | 6.1 - MEDIUM | 2023-10-13 | 2023-11-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Fortinet | Fortisandbox | 3.0.4 | |||
| Application | Fortinet | Fortisandbox | 3.0.3 | |||
| Application | Fortinet | Fortisandbox | 3.0.2 | |||
| Application | Fortinet | Fortisandbox | 3.0.1 | |||
| Application | Fortinet | Fortisandbox | 3.0.0 | |||
| Application | Fortinet | Fortisandbox | 2.5.2 | |||
| Application | Fortinet | Fortisandbox | 2.5.1 | |||
| Application | Fortinet | Fortisandbox | 2.5.0 | |||
| Application | Fortinet | Fortisandbox | 2.4.1 | |||
| Application | Fortinet | Fortisandbox | 2.4.0 | |||
| Application | Fortinet | Fortisandbox | 2.3.3 | |||
| Application | Fortinet | Fortisandbox | 2.3.2 | |||
| Application | Fortinet | Fortisandbox | 2.3.0 | |||
| Application | Fortinet | Fortisandbox | 2.2.2 | |||
| Application | Fortinet | Fortisandbox | 2.2.1 | |||
| Application | Fortinet | Fortisandbox | 2.2.0 | |||
| Application | Fortinet | Fortisandbox | 2.1.3 | |||
| Application | Fortinet | Fortisandbox | 2.1.2 | |||
| Application | Fortinet | Fortisandbox | 2.1.1 | |||
| Application | Fortinet | Fortisandbox | 2.1.0 |