CVE-2026-64947High· 7.5▾ TwilightA chained CSRF bypass and unrestricted file upload vulnerability in the Plugin File Manager allows an attacker to upload and execute arbitrary PHP code, resulting in Remote Code Execution. This issue affects Pandora FMS: from 777 onwards.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A chained CSRF bypass and unrestricted file upload vulnerability in the Plugin File Manager allows an attacker to upload and execute arbitrary PHP code, resulting in Remote Code Execution. This issue affects Pandora FMS: from 777 onwards.
pandora_fms 777Fixed v800.5 and v805
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-34190Medium· 5.9CSRF in Alert Command Deletion
CVE-2026-64946High· 7.4CSRF Bypass Leading to Stored Cross-Site Scripting via Unrestricted SVG Upload in File Manager
CVE-2026-34189Medium· 5.9CSRF in Event Response Deletion
CVE-2026-64949High· 8.6Unrestricted File Upload Leading to Remote Code Execution in Admin Tools File Manager
CVE-2026-64950High· 8.4Stored Cross-Site Scripting via Directory Name in File Manager Create Directory
CVE-2026-75786High· 7.2SQL Injection in Grafana Integration Endpoint (query.php)