CVE-2026-64946High· 7.4▾ TwilightA chained CSRF and unrestricted SVG file upload vulnerability in the File Manager module allows stored Cross-Site Scripting, enabling session cookie exfiltration and administrator account takeover. This issue affects Pandora FMS: from 77…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A chained CSRF and unrestricted SVG file upload vulnerability in the File Manager module allows stored Cross-Site Scripting, enabling session cookie exfiltration and administrator account takeover. This issue affects Pandora FMS: from 777 onwards.
pandora_fms 777Fixed v800.5 and v805
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-34190Medium· 5.9CSRF in Alert Command Deletion
CVE-2026-34189Medium· 5.9CSRF in Event Response Deletion
CVE-2026-64950High· 8.4Stored Cross-Site Scripting via Directory Name in File Manager Create Directory
CVE-2026-64947High· 7.5CSRF Bypass Leading to Remote Code Execution via Unrestricted File Upload in Plugin File Manager
CVE-2026-75786High· 7.2SQL Injection in Grafana Integration Endpoint (query.php)
CVE-2026-64948High· 7.1Missing Authorization in get_module_detail AJAX Endpoint Allows Cross-Group Module Data Disclosure