Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Pandora FMS — Vulnerabilities & Security Advisories 56

Browse all 56 CVE security advisories affecting Pandora FMS. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Pandora FMS is an open-source network monitoring and management solution designed to provide comprehensive visibility into IT infrastructure performance and availability. Historically, its codebase has exhibited significant security weaknesses, resulting in forty-three recorded Common Vulnerabilities and Exposures. These flaws predominantly involve remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from insufficient input validation and improper access controls within its web interface and API components. While the platform serves critical operational needs for system administrators, the high volume of disclosed CVEs indicates a pattern of recurring security defects that require diligent patching. No single catastrophic incident has publicly defined the software’s reputation, but the cumulative risk profile suggests that organizations must prioritize rigorous security hardening and regular updates to mitigate the potential for unauthorized system access or data compromise inherent in its current vulnerability landscape.

Found 54 results / 56 Clear Filters
Top products by Pandora FMS: Pandora FMS Pandora ITSM
CVE ID Title CVSS Severity Published
CVE-2024-35304 System command injection through Netflow function — Pandora FMS CWE-78 9.8 - 2024-06-10
CVE-2023-41793 Path Traversal and Untrusted Upload File — Pandora FMS CWE-35 6.7 Medium 2024-03-19
CVE-2023-44092 OS Command Injection — Pandora FMS CWE-78 7.6 High 2024-03-19
CVE-2023-44091 Unauth Time-Based SQL Injection — Pandora FMS CWE-89 7.5 High 2024-03-19
CVE-2023-44090 UnautH SQL Injection — Pandora FMS CWE-89 6.8 Medium 2024-03-19
CVE-2023-44089 XSS in Visual Console — Pandora FMS CWE-79 6.1 Medium 2023-12-29
CVE-2023-44088 SQL Injection in Visual Console — Pandora FMS CWE-89 5.9 Medium 2023-12-29
CVE-2023-41815 XSS in File manager — Pandora FMS CWE-79 7.5 High 2023-12-29
CVE-2023-41814 XSS Vulnerability Messages — Pandora FMS CWE-79 3.7 Low 2023-12-29
CVE-2023-41813 User notification settings edition — Pandora FMS CWE-79 3.0 Low 2023-12-29
CVE-2023-41812 Uploading executables via the file manager — Pandora FMS CWE-434 5.7 Medium 2023-11-23
CVE-2023-41811 Stored XSS Via Site News Page — Pandora FMS CWE-79 5.3 Medium 2023-11-23
CVE-2023-41810 Stored XSS Via Dashboard Panel — Pandora FMS CWE-79 4.0 Medium 2023-11-23
CVE-2023-41808 Arbitrary File Read As Root Via GoTTY Page — Pandora FMS CWE-269 8.5 High 2023-11-23
CVE-2023-41807 Linux Local Privilege Escalation Via GoTTY Page — Pandora FMS CWE-269 9.1 Critical 2023-11-23
CVE-2023-41806 Misassignment of privileges can cause DOS attack — Pandora FMS CWE-269 8.2 High 2023-11-23
CVE-2023-41792 Lack of Authorization and Stored XSS Via SNMP Trap Editor Page — Pandora FMS CWE-352 5.9 Medium 2023-11-23
CVE-2023-41791 Lack of Authorization and Stored XSS Via Translation Abuse — Pandora FMS CWE-79 8.4 High 2023-11-23
CVE-2023-41790 Traversal Path on PHP file — Pandora FMS CWE-427 7.6 High 2023-11-23
CVE-2023-41789 Unauthenticated Admin Account Takeover Via XSS — Pandora FMS CWE-79 7.6 High 2023-11-23
CVE-2023-41788 Remote Code Execution via File Uploader — Pandora FMS CWE-434 7.6 High 2023-11-23
CVE-2023-41787 Arbitrary File Read — Pandora FMS CWE-427 6.0 Medium 2023-11-23
CVE-2023-41786 Database backups availability by low-privileged users — Pandora FMS CWE-200 6.8 Medium 2023-11-23
CVE-2023-4677 Unauthenticated Admin Account Takeover Via Cron Log File Backups — Pandora FMS CWE-287 7.0 High 2023-11-23

This page lists every published CVE security advisory associated with Pandora FMS. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.