CVE-2026-34189Medium· 5.9▾ SunlitCross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of event responses via a forged GET request when an authenticated administrator visits a malicious page. This issue affects Pandora FMS: from 777 onwards.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of event responses via a forged GET request when an authenticated administrator visits a malicious page. This issue affects Pandora FMS: from 777 onwards.
pandora_fms 777Fixed v805 an v800.5
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-34190Medium· 5.9CSRF in Alert Command Deletion
CVE-2026-64946High· 7.4CSRF Bypass Leading to Stored Cross-Site Scripting via Unrestricted SVG Upload in File Manager
CVE-2026-64947High· 7.5CSRF Bypass Leading to Remote Code Execution via Unrestricted File Upload in Plugin File Manager
CVE-2026-64950High· 8.4Stored Cross-Site Scripting via Directory Name in File Manager Create Directory
CVE-2026-75786High· 7.2SQL Injection in Grafana Integration Endpoint (query.php)
CVE-2026-64948High· 7.1Missing Authorization in get_module_detail AJAX Endpoint Allows Cross-Group Module Data Disclosure