CVE-2025-31366

An Improper Neutralization of Input During Web Page Generation vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions, FortiSASE 25.2.a may allow an unauthenticated attacker to perform a reflected cross site scripting (XSS) via crafted HTTP requests.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:fortinet:fortisase:25.3.40:*:*:*:feature:*:*:*
cpe:2.3:a:fortinet:fortisase:25.3.40:*:*:*:mature:*:*:*

History

No history.

Information

Published : 2025-10-14 16:15

Updated : 2026-01-14 10:16


NVD link : CVE-2025-31366

Mitre link : CVE-2025-31366

CVE.ORG link : CVE-2025-31366


JSON object : View

Products Affected

fortinet

  • fortiproxy
  • fortios
  • fortisase
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')