CVE-2025-61886

MEDIUMCVSS 5.40% EPSS

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4, FortiSandbox PaaS 5.0.0 through 5.0.4 may allow an attacker to perform an XSS attack via crafted HTTP requests.

Published 2026-04-14 · last modified 2026-06-17

Affected products

VendorProduct
fortinetfortisandbox
fortinetfortisandbox_cloud

Full record at NVD ↗

← Get alerted the moment a CVE hits your gear — subscribe free

Ncerio by BeyondNets · data from NVD, CISA KEV, EPSS.