One of the high-severity issues is a persistent cross-site scripting issue (CVE-2022-3837) in Log pages of FortiADC. A remote, unauthenticated attacker could trigger the flaw to perform a stored XSS attack via HTTP fields observed in the traffic and event logviews.
Another issue rated high is in FortiTester (CVE-2022-33870) which could allow an authenticated attacker to execute commands via specially crafted arguments to existing commands.
A high-rated vulnerability with a case number of CVE-2022-26119 affects FortiSIEM, where a local attacker with command-line access can exploit the bug to perform operations on the Glassfish server directly via a hardcoded password.
Another high rated vulnerability is an improper neutralization of input during web page generation vulnerability in FortiADC management interface that may allow a remote and authenticated attacker to trigger a stored cross site scripting (XSS) attack via configuring a specially crafted IP Address.
Products affected by the vulnerability, which has a case number of CVE-2022-35851, are FortiADC version 7.1.0, with a fix in version 7.1.1 or above.
Click here for more in the other vulnerabilities.

