pandora_fms vulnerabilities
CVEs whose affected-version data names the pandora_fms package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2025-34088High· 8.8PoCAn authenticated remote code execution vulnerability exists in Pandora FMS version 7.0NG and earlier
An authenticated remote code execution vulnerability exists in Pandora FMS version 7.0NG and earlier. The net_tools.php functionality allows authenticated users to execute arbitrary OS commands via the select_ips parameter when performin…
CVE-2021-36698Medium· 5.4Pandora FMS through 755 allows XSS via a new Event Filter with a crafted name.
Pandora FMS through 755 allows XSS via a new Event Filter with a crafted name.
CVE-2021-36697Medium· 6.7With an admin account, the .htaccess file in Artica Pandora FMS <=755 can be overwritten with the File Manager component
With an admin account, the .htaccess file in Artica Pandora FMS <=755 can be overwritten with the File Manager component. The new .htaccess file contains a Rewrite Rule with a type definition. A normal PHP file can be uploaded with this …