CVE-2019-16151: Fortinet FortiOS

Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS 6.4.1 and below, 6.2.9 and below may allow a remote unauthenticated attacker to either redirect users to malicious websites via a crafted "Host" header or to execute JavaScript code in the victim's browser context. This happens when the FortiGate has web filtering and category override enabled/configured.

Affected products

  • Fortinet FortiOS: from 6.2.0, before 6.2.10 (fixed in 6.2.10); from 6.4.0, before 6.4.2 (fixed in 6.4.2)

Published 2025-03-21. Last modified 2026-06-17.