Sploitus

CVE-2025-25257

17 known exploits for CVE-2025-25257

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.7, FortiWeb 7.2.0 through 7.2.10, FortiWeb 7.0.0 through 7.0.10 allows an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.

Affected products
Fortiweb
Fortinet Fortiweb
< 7.0.11, 7.2.11, 7.4.8, 7.6.4
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
96.7% (100th percentile)
Weakness
CWE-89
NVD status
Analyzed
Published
2025-07-17

Fix

Upgrade to FortiWeb version 7.6.4 or above Upgrade to FortiWeb version 7.4.8 or above Upgrade to FortiWeb version 7.2.11 or above Upgrade to FortiWeb version 7.0.11 or above

CVE-2025-25257 at NVD
Authoritative description, scoring and affected products

17 known exploits for CVE-2025-25257

Proof-of-concept code and exploit modules indexed by Sploitus