---
id: CVE-2025-31366
title: >-
  An Improper Neutralization of Input During Web Page Generation vulnerability
  [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0
  through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4
  all…
summary: >-
  An Improper Neutralization of Input During Web Page Generation vulnerability
  [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0
  through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4
  all…
severity: medium
cvss: 4.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: fortinet
product: fortiproxy
affected:
  - 'fortios >= 6.4.0, < 7.4.9'
  - 'fortios >= 7.6.0, < 7.6.4'
  - 'fortiproxy >= 7.0.0, < 7.6.4'
  - fortisase = 25.3.40
patched:
  - fortios 7.6.4
  - fortiproxy 7.6.4
published: '2025-10-14'
updated: '2026-07-08'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-31366'
references:
  - url: 'https://fortiguard.fortinet.com/psirt/FG-IR-24-542'
    label: psirt@fortinet.com
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-864900.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
tags:
  - nvd
epss: 0.00398
epssPercentile: 0.33821
ingestedAt: '2026-07-08T13:51:10.421Z'
---

## Overview

An Improper Neutralization of Input During Web Page Generation vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions, FortiSASE 25.2.a may allow an unauthenticated attacker to perform a reflected cross site scripting (XSS) via crafted HTTP requests.

## Affected

- `fortios >= 6.4.0, < 7.4.9`
- `fortios >= 7.6.0, < 7.6.4`
- `fortiproxy >= 7.0.0, < 7.6.4`
- `fortisase = 25.3.40`

## Remediation

Upgrade past the affected range:

- `fortios 7.6.4`
- `fortiproxy 7.6.4`
