CVE-2025-61886
EUVD-2025-20945514.04.2026, 16:16
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4, FortiSandbox PaaS 5.0.0 through 5.0.4 may allow an attacker to perform an XSS attack via crafted HTTP requests.Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| fortinet | fortisandbox | 5.0.0 ≤ 𝑥 < 5.0.5 |
| fortinet | fortisandbox_cloud | 5.0.4 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| fortinet | fortisandbox_paas | 5.0.0 ≤ 𝑥 ≤ 5.0.4 | CNA |