CVE-2026-64950High· 8.4▾ TwilightMissing input validation and output encoding on the directory name parameter in File Manager's Create Directory allows stored XSS, executing without user interaction. Affects Pandora FMS from 777 onwards.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 46.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Missing input validation and output encoding on the directory name parameter in File Manager's Create Directory allows stored XSS, executing without user interaction. Affects Pandora FMS from 777 onwards.
pandora_fms 777Fixed v800.5 and v805
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-64946High· 7.4CSRF Bypass Leading to Stored Cross-Site Scripting via Unrestricted SVG Upload in File Manager
CVE-2026-34190Medium· 5.9CSRF in Alert Command Deletion
CVE-2026-34189Medium· 5.9CSRF in Event Response Deletion
CVE-2026-64947High· 7.5CSRF Bypass Leading to Remote Code Execution via Unrestricted File Upload in Plugin File Manager
CVE-2026-75786High· 7.2SQL Injection in Grafana Integration Endpoint (query.php)
CVE-2026-64948High· 7.1Missing Authorization in get_module_detail AJAX Endpoint Allows Cross-Group Module Data Disclosure