Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Pandora FMS — Vulnerabilities & Security Advisories 84

All 84 CVE vulnerabilities found in Pandora FMS, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability records for Pandora FMS, a free open-source Field Maintenance Service (FMS) software, covering specific weakness types and security tags. The collection includes historical advisories, bug reports, and security patches related to input validation, access control, and injection flaws over the product's development timeline. Readers can use this index to track vendor-issued security updates, analyze recurring weakness patterns, and review the full vulnerability history for Pandora FMS instances.

Vendor: Artica PFMS

CVE ID Title CVSS Severity Published
CVE-2024-35307 Argument Injection Leading to Remote Code Execution in Realtime Graph Extension CWE-88 9.8 - 2024-06-10
CVE-2024-35306 OS Command injection in Ajax PHP files through HTTP Request CWE-78 9.8 - 2024-06-10
CVE-2024-35305 Unauth Time-Based SQL Injection via API CWE-89 9.8 - 2024-06-10
CVE-2024-35304 System command injection through Netflow function CWE-78 9.8 - 2024-06-10
CVE-2023-41793 Path Traversal and Untrusted Upload File CWE-35 6.7 Medium 2024-03-19
CVE-2023-44092 OS Command Injection CWE-78 7.6 High 2024-03-19
CVE-2023-44091 Unauth Time-Based SQL Injection CWE-89 7.5 High 2024-03-19
CVE-2023-44090 UnautH SQL Injection CWE-89 6.8 Medium 2024-03-19
CVE-2023-44089 XSS in Visual Console CWE-79 6.1 Medium 2023-12-29
CVE-2023-44088 SQL Injection in Visual Console CWE-89 5.9 Medium 2023-12-29
CVE-2023-41815 XSS in File manager CWE-79 7.5 High 2023-12-29
CVE-2023-41814 XSS Vulnerability Messages CWE-79 3.7 Low 2023-12-29
CVE-2023-41813 User notification settings edition CWE-79 3.0 Low 2023-12-29
CVE-2023-41812 Uploading executables via the file manager CWE-434 5.7 Medium 2023-11-23
CVE-2023-41811 Stored XSS Via Site News Page CWE-79 5.3 Medium 2023-11-23
CVE-2023-41810 Stored XSS Via Dashboard Panel CWE-79 4.0 Medium 2023-11-23
CVE-2023-41808 Arbitrary File Read As Root Via GoTTY Page CWE-269 8.5 High 2023-11-23
CVE-2023-41807 Linux Local Privilege Escalation Via GoTTY Page CWE-269 9.1 Critical 2023-11-23
CVE-2023-41806 Misassignment of privileges can cause DOS attack CWE-269 8.2 High 2023-11-23
CVE-2023-41792 Lack of Authorization and Stored XSS Via SNMP Trap Editor Page CWE-352 5.9 Medium 2023-11-23
CVE-2023-41791 Lack of Authorization and Stored XSS Via Translation Abuse CWE-79 8.4 High 2023-11-23
CVE-2023-41790 Traversal Path on PHP file CWE-427 7.6 High 2023-11-23
CVE-2023-41789 Unauthenticated Admin Account Takeover Via XSS CWE-79 7.6 High 2023-11-23
CVE-2023-41788 Remote Code Execution via File Uploader CWE-434 7.6 High 2023-11-23
CVE-2023-41787 Arbitrary File Read CWE-427 6.0 Medium 2023-11-23
CVE-2023-41786 Database backups availability by low-privileged users CWE-200 6.8 Medium 2023-11-23
CVE-2023-4677 Unauthenticated Admin Account Takeover Via Cron Log File Backups CWE-287 7.0 High 2023-11-23
CVE-2023-0828 Stored Cross Site Scripting in syslog section CWE-79 6.7 Medium 2023-10-03
CVE-2023-24518 Disabling the administrator's account through cross-site request forgery CWE-352 6.7 Medium 2023-10-03
CVE-2023-24517 Remote Code Execution via Unrestricted File Upload CWE-434 6.4 Medium 2023-08-22

All 84 known CVE vulnerabilities affecting Pandora FMS with full Chinese analysis, references, and POCs where available.