CVE-2026-75786High· 7.2▾ TwilightUnsanitized concatenation of the module parameter in the Grafana datasource endpoint allows authenticated blind SQL injection. Affects Pandora FMS from 777 onwards.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Unsanitized concatenation of the module parameter in the Grafana datasource endpoint allows authenticated blind SQL injection. Affects Pandora FMS from 777 onwards.
pandora_fms 777Fixed v800.6 and v805
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-34190Medium· 5.9CSRF in Alert Command Deletion
CVE-2026-64946High· 7.4CSRF Bypass Leading to Stored Cross-Site Scripting via Unrestricted SVG Upload in File Manager
CVE-2026-34189Medium· 5.9CSRF in Event Response Deletion
CVE-2026-64950High· 8.4Stored Cross-Site Scripting via Directory Name in File Manager Create Directory
CVE-2026-64947High· 7.5CSRF Bypass Leading to Remote Code Execution via Unrestricted File Upload in Plugin File Manager
CVE-2026-64948High· 7.1Missing Authorization in get_module_detail AJAX Endpoint Allows Cross-Group Module Data Disclosure