Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Pandora FMS — Vulnerabilities & Security Advisories 84

All 84 CVE vulnerabilities found in Pandora FMS, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability records for Pandora FMS, a free open-source Field Maintenance Service (FMS) software, covering specific weakness types and security tags. The collection includes historical advisories, bug reports, and security patches related to input validation, access control, and injection flaws over the product's development timeline. Readers can use this index to track vendor-issued security updates, analyze recurring weakness patterns, and review the full vulnerability history for Pandora FMS instances.

Vendor: Artica PFMS

CVE ID Title CVSS Severity Published
CVE-2026-75786 SQL Injection in Grafana Integration Endpoint (query.php) CWE-89 7.2 High 2026-10-01
CVE-2026-64950 Stored Cross-Site Scripting via Directory Name in File Manager Create Directory CWE-79 8.4 High 2026-10-01
CVE-2026-64949 Unrestricted File Upload Leading to Remote Code Execution in Admin Tools File Manager CWE-434 8.6 High 2026-10-01
CVE-2026-64948 Missing Authorization in get_module_detail AJAX Endpoint Allows Cross-Group Module Data Disclosure CWE-639 7.1 High 2026-10-01
CVE-2026-64947 CSRF Bypass Leading to Remote Code Execution via Unrestricted File Upload in Plugin File Manager CWE-434 7.5 High 2026-10-01
CVE-2026-64946 CSRF Bypass Leading to Stored Cross-Site Scripting via Unrestricted SVG Upload in File Manager CWE-79 7.4 High 2026-10-01
CVE-2026-34190 CSRF in Alert Command Deletion CWE-352 5.9 Medium 2026-10-01
CVE-2026-34189 CSRF in Event Response Deletion CWE-352 5.9 Medium 2026-10-01
CVE-2026-34187 SQL Injection in Graph Container Parameter CWE-89 - - 2026-05-12
CVE-2026-30810 Server-Side Request Forgery in API Checker leads to Privilege Escalation CWE-918 - - 2026-05-12
CVE-2026-30808 Session Fixation in Authentication leads to Session Hijacking CWE-384 - - 2026-05-12
CVE-2026-30807 Cross-Site Request Forgery on Extension Pages CWE-352 - - 2026-05-12
CVE-2026-30805 Insecure Default Initialization in API Authentication leads to Authentication Bypass CWE-1188 - - 2026-05-12
CVE-2026-34188 OS Command Injection in Event Response Execution CWE-78 9.8 - 2026-04-13
CVE-2026-34186 SQL Injection in Custom Fields leads to Database Compromise CWE-89 9.8 - 2026-04-13
CVE-2026-30813 SQL Injection in Module Search leads to Database Compromise CWE-89 9.8 - 2026-04-13
CVE-2026-30812 Stored Cross-Site Scripting in Event Comments via Filter Bypass CWE-79 6.1 - 2026-04-13
CVE-2026-30811 Missing Authorization in Configuration Ajax Endpoint leads to Information Disclosure CWE-276 7.5 - 2026-04-13
CVE-2026-30809 OS Command Injection in WebServerModuleDebug via Blacklist Bypass leads to Remote Code Execution CWE-78 9.8 - 2026-04-13
CVE-2026-30806 OS Command Injection in Network Report leads to Remote Code Execution CWE-78 9.8 - 2026-04-13
CVE-2026-30804 Unrestricted File Upload in Extension Uploader leads to Remote Code Execution CWE-434 9.8 - 2026-04-13
CVE-2014-125124 Pandora FMS <= 5.0RC1 Anyterm Unauthenticated Command Injection CWE-78 9.8AI Critical AI 2025-07-31
CVE-2014-125115 Pandora FMS ≤ 5.0 SP2 Default Credential SQL Injection RCE CWE-798 9.8 - 2025-07-25
CVE-2025-34088 Pandora FMS Authenticated Remote Code Execution via Ping Module CWE-78 8.8AI High AI 2025-07-03
CVE-2025-5306 Command Injection in Netflow path CWE-77 9.8AI Critical AI 2025-06-27
CVE-2024-12992 Remote Code Execution leads to Command Injection CWE-77 9.8 - 2025-03-17
CVE-2024-12971 QuickShell Authenticated Command Injection CWE-77 9.8 - 2025-03-17
CVE-2024-11320 Command Injection leading to RCE via LDAP Misconfiguration CWE-77 9.8AI Critical AI 2024-11-21
CVE-2024-35308 Post-auth Arbitrary File Read in the Server Plugins Section CWE-22 6.5AI Medium AI 2024-10-22
CVE-2024-9987 SQL Injection in CSV Module Data Collection CWE-89 8.8AI High AI 2024-10-22

All 84 known CVE vulnerabilities affecting Pandora FMS with full Chinese analysis, references, and POCs where available.