VulnSea

Pandora FMS has 8 CVEs on record. Disclosure cadence is accelerating: 8 in the last 90 days against 0 in the 90 before. The busiest recent month was October 2026 with 8. The median CVSS is 7.3 (high). None have a confirmed exploitation report. The most common weakness class is CWE-352 (4).

CVEs per month

Last 12 months, by publish date

111201020304050607080910
Exploited share
0% vs 1% corpus
Median CVSS
7.3
Publish → KEV
—
Last 90 days
8 prev 0

Products

  • Pandora FMS 8
8
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

Pandora FMS vulnerabilities

CVEs affecting Pandora FMS, newest first. Open any entry for full detail, references, and exploit status.

8 CVEsRSS

CVE-2026-64946High· 7.4
today

CSRF Bypass Leading to Stored Cross-Site Scripting via Unrestricted SVG Upload in File Manager

A chained CSRF and unrestricted SVG file upload vulnerability in the File Manager module allows stored Cross-Site Scripting, enabling session cookie exfiltration and administrator account takeover. This issue affects Pandora FMS: from 77…

▾ TwilightPandora FMS · Pandora FMSvia CVEORG
CVE-2026-34190Medium· 5.9
today

CSRF in Alert Command Deletion

Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of alert commands via sequential, unvalidated GET requests when an authenticated administrator visits a malicious page. This issue affects Pandora FMS: from 777…

▾ SunlitPandora FMS · Pandora FMSvia CVEORG
CVE-2026-34189Medium· 5.9
today

CSRF in Event Response Deletion

Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of event responses via a forged GET request when an authenticated administrator visits a malicious page. This issue affects Pandora FMS: from 777 onwards.

▾ SunlitPandora FMS · Pandora FMSvia CVEORG
CVE-2026-64950High· 8.4
today

Stored Cross-Site Scripting via Directory Name in File Manager Create Directory

Missing input validation and output encoding on the directory name parameter in File Manager's Create Directory allows stored XSS, executing without user interaction. Affects Pandora FMS from 777 onwards.

▾ TwilightPandora FMS · Pandora FMSvia CVEORG
CVE-2026-64947High· 7.5
today

CSRF Bypass Leading to Remote Code Execution via Unrestricted File Upload in Plugin File Manager

A chained CSRF bypass and unrestricted file upload vulnerability in the Plugin File Manager allows an attacker to upload and execute arbitrary PHP code, resulting in Remote Code Execution. This issue affects Pandora FMS: from 777 onwards.

▾ TwilightPandora FMS · Pandora FMSvia CVEORG
CVE-2026-75786High· 7.2
today

SQL Injection in Grafana Integration Endpoint (query.php)

Unsanitized concatenation of the module parameter in the Grafana datasource endpoint allows authenticated blind SQL injection. Affects Pandora FMS from 777 onwards.

▾ TwilightPandora FMS · Pandora FMSvia CVEORG
CVE-2026-64949High· 8.6
today

Unrestricted File Upload Leading to Remote Code Execution in Admin Tools File Manager

Incomplete extension blacklist in the File Manager module allows authenticated upload and execution of arbitrary .phar files. Affects Pandora FMS from 777 onwards.

▾ TwilightPandora FMS · Pandora FMSvia CVEORG
CVE-2026-64948High· 7.1
today

Missing Authorization in get_module_detail AJAX Endpoint Allows Cross-Group Module Data Disclosure

Missing authorization in module data retrieval allows unauthorized cross-group access to module history. Affects Pandora FMS from 777 onwards.

▾ TwilightPandora FMS · Pandora FMSvia CVEORG
Pandora FMS vulnerabilities (CVEs) · VulnSea