Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Pandora FMS — Vulnerabilities & Security Advisories 56

Browse all 56 CVE security advisories affecting Pandora FMS. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Pandora FMS is an open-source network monitoring and management solution designed to provide comprehensive visibility into IT infrastructure performance and availability. Historically, its codebase has exhibited significant security weaknesses, resulting in forty-three recorded Common Vulnerabilities and Exposures. These flaws predominantly involve remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from insufficient input validation and improper access controls within its web interface and API components. While the platform serves critical operational needs for system administrators, the high volume of disclosed CVEs indicates a pattern of recurring security defects that require diligent patching. No single catastrophic incident has publicly defined the software’s reputation, but the cumulative risk profile suggests that organizations must prioritize rigorous security hardening and regular updates to mitigate the potential for unauthorized system access or data compromise inherent in its current vulnerability landscape.

Top products by Pandora FMS: Pandora FMS Pandora ITSM
CVE ID Title CVSS Severity Published
CVE-2026-75786 SQL Injection in Grafana Integration Endpoint (query.php) — Pandora FMS CWE-89 7.2 High 2026-10-01
CVE-2026-64950 Stored Cross-Site Scripting via Directory Name in File Manager Create Directory — Pandora FMS CWE-79 8.4 High 2026-10-01
CVE-2026-64949 Unrestricted File Upload Leading to Remote Code Execution in Admin Tools File Manager — Pandora FMS CWE-434 8.6 High 2026-10-01
CVE-2026-64948 Missing Authorization in get_module_detail AJAX Endpoint Allows Cross-Group Module Data Disclosure — Pandora FMS CWE-639 7.1 High 2026-10-01
CVE-2026-64947 CSRF Bypass Leading to Remote Code Execution via Unrestricted File Upload in Plugin File Manager — Pandora FMS CWE-434 7.5 High 2026-10-01
CVE-2026-64946 CSRF Bypass Leading to Stored Cross-Site Scripting via Unrestricted SVG Upload in File Manager — Pandora FMS CWE-79 7.4 High 2026-10-01
CVE-2026-34190 CSRF in Alert Command Deletion — Pandora FMS CWE-352 5.9 Medium 2026-10-01
CVE-2026-34189 CSRF in Event Response Deletion — Pandora FMS CWE-352 5.9 Medium 2026-10-01
CVE-2026-34187 SQL Injection in Graph Container Parameter — Pandora FMS CWE-89 - - 2026-05-12
CVE-2026-30810 Server-Side Request Forgery in API Checker leads to Privilege Escalation — Pandora FMS CWE-918 - - 2026-05-12
CVE-2026-30808 Session Fixation in Authentication leads to Session Hijacking — Pandora FMS CWE-384 - - 2026-05-12
CVE-2026-30807 Cross-Site Request Forgery on Extension Pages — Pandora FMS CWE-352 - - 2026-05-12
CVE-2026-30805 Insecure Default Initialization in API Authentication leads to Authentication Bypass — Pandora FMS CWE-1188 - - 2026-05-12
CVE-2026-34188 OS Command Injection in Event Response Execution — Pandora FMS CWE-78 9.8 - 2026-04-13
CVE-2026-34186 SQL Injection in Custom Fields leads to Database Compromise — Pandora FMS CWE-89 9.8 - 2026-04-13
CVE-2026-30813 SQL Injection in Module Search leads to Database Compromise — Pandora FMS CWE-89 9.8 - 2026-04-13
CVE-2026-30812 Stored Cross-Site Scripting in Event Comments via Filter Bypass — Pandora FMS CWE-79 6.1 - 2026-04-13
CVE-2026-30811 Missing Authorization in Configuration Ajax Endpoint leads to Information Disclosure — Pandora FMS CWE-276 7.5 - 2026-04-13
CVE-2026-30809 OS Command Injection in WebServerModuleDebug via Blacklist Bypass leads to Remote Code Execution — Pandora FMS CWE-78 9.8 - 2026-04-13
CVE-2026-30806 OS Command Injection in Network Report leads to Remote Code Execution — Pandora FMS CWE-78 9.8 - 2026-04-13
CVE-2026-30804 Unrestricted File Upload in Extension Uploader leads to Remote Code Execution — Pandora FMS CWE-434 9.8 - 2026-04-13
CVE-2025-5306 Command Injection in Netflow path — Pandora FMS CWE-77 9.8AI Critical AI 2025-06-27
CVE-2025-4678 Remote Code Execution leads to Command Injection — Pandora ITSM CWE-77 9.8AI Critical AI 2025-06-10
CVE-2025-4653 Remote Code Execution leads to Command Injection — Pandora ITSM CWE-77 9.8AI Critical AI 2025-06-10
CVE-2024-12992 Remote Code Execution leads to Command Injection — Pandora FMS CWE-77 9.8 - 2025-03-17
CVE-2024-12971 QuickShell Authenticated Command Injection — Pandora FMS CWE-77 9.8 - 2025-03-17
CVE-2024-11320 Command Injection leading to RCE via LDAP Misconfiguration — Pandora FMS CWE-77 9.8AI Critical AI 2024-11-21
CVE-2024-35308 Post-auth Arbitrary File Read in the Server Plugins Section — Pandora FMS CWE-22 6.5AI Medium AI 2024-10-22
CVE-2024-9987 SQL Injection in CSV Module Data Collection — Pandora FMS CWE-89 8.8AI High AI 2024-10-22
CVE-2024-35307 Argument Injection Leading to Remote Code Execution in Realtime Graph Extension — Pandora FMS CWE-88 9.8 - 2024-06-10

This page lists every published CVE security advisory associated with Pandora FMS. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.