MEDIUMCVSS 4.80% EPSS
A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox PaaS 5.0.0 through 5.0.5, FortiSandbox PaaS 4.4.0 through 4.4.8, FortiSandbox PaaS 4.2 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>
Published 2026-04-14 · last modified 2026-06-17
| Vendor | Product |
|---|---|
| fortinet | fortisandbox |
| fortinet | fortisandbox_cloud |
Ncerio by BeyondNets · data from NVD, CISA KEV, EPSS.