CVE-2019-16156: Fortinet FortiWeb
Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.
An Improper Neutralization of Input vulnerability in the Anomaly Detection Parameter Name in Fortinet FortiWeb 6.0.5, 6.2.0, and 6.1.1 may allow a remote unauthenticated attacker to perform a Cross Site Scripting attack (XSS).
Affected products
- Fortinet FortiWeb: from 6.0.0, up to and including 6.0.5; from 6.1.0, up to and including 6.1.1; version 6.2.0 only
Published 2020-03-12. Last modified 2026-06-17.