Pandora FMS

8 known vulnerabilities in Pandora FMS, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-75786 CVSS 7.2 high Unsanitized concatenation of the module parameter in the Grafana datasource endpoint allows authenticated blind SQL injection. Affects…
  • CVE-2026-64950 CVSS 8.4 high Missing input validation and output encoding on the directory name parameter in File Manager's Create Directory allows stored XSS…
  • CVE-2026-64949 CVSS 8.6 high Incomplete extension blacklist in the File Manager module allows authenticated upload and execution of arbitrary .phar files. Affects…
  • CVE-2026-64948 CVSS 7.1 high Missing authorization in module data retrieval allows unauthorized cross-group access to module history. Affects Pandora FMS from 777…
  • CVE-2026-64947 CVSS 7.5 high A chained CSRF bypass and unrestricted file upload vulnerability in the Plugin File Manager allows an attacker to upload and execute…
  • CVE-2026-64946 CVSS 7.4 high A chained CSRF and unrestricted SVG file upload vulnerability in the File Manager module allows stored Cross-Site Scripting, enabling…
  • CVE-2026-34190 CVSS 5.9 medium Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of alert commands via sequential, unvalidated GET requests…
  • CVE-2026-34189 CVSS 5.9 medium Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of event responses via a forged GET request when an…