---
id: CVE-2025-54353
title: >-
  An Improper Neutralization of Input During Web Page Generation ('Cross-site
  Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox
  5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all
  versions, F…
summary: >-
  An Improper Neutralization of Input During Web Page Generation ('Cross-site
  Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox
  5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all
  versions, F…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: fortinet
product: fortisandbox
affected:
  - 'fortisandbox >= 4.0.0, <= 4.0.6'
  - 'fortisandbox >= 4.2.0, <= 4.2.8'
  - 'fortisandbox >= 4.4.0, <= 4.4.7'
  - 'fortisandbox >= 5.0.0, <= 5.0.2'
published: '2025-12-09'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T10:10:00.227'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-54353'
references:
  - url: 'https://fortiguard.fortinet.com/psirt/FG-IR-25-477'
    label: psirt@fortinet.com
tags:
  - nvd
epss: 0.06313
epssPercentile: 0.93433
ingestedAt: '2026-10-08T10:28:24.326Z'
---

## Overview

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an attacker to perform an XSS attack via crafted HTTP requests.

## Affected

- `fortisandbox >= 4.0.0, <= 4.0.6`
- `fortisandbox >= 4.2.0, <= 4.2.8`
- `fortisandbox >= 4.4.0, <= 4.4.7`
- `fortisandbox >= 5.0.0, <= 5.0.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
