CVE-2026-75786
- EPSS 0.2%
- Veröffentlicht 01.10.2026 09:30:48
- Zuletzt bearbeitet 01.10.2026 20:17:30
Unsanitized concatenation of the module parameter in the Grafana datasource endpoint allows authenticated blind SQL injection. Affects Pandora FMS from 777 onwards.
CVE-2026-64950
- EPSS 0.25%
- Veröffentlicht 01.10.2026 09:30:09
- Zuletzt bearbeitet 01.10.2026 20:17:28
Missing input validation and output encoding on the directory name parameter in File Manager's Create Directory allows stored XSS, executing without user interaction. Affects Pandora FMS from 777 onwards.
CVE-2026-64949
- EPSS 0.3%
- Veröffentlicht 01.10.2026 09:29:30
- Zuletzt bearbeitet 01.10.2026 20:17:28
Incomplete extension blacklist in the File Manager module allows authenticated upload and execution of arbitrary .phar files. Affects Pandora FMS from 777 onwards.
CVE-2026-64948
- EPSS 0.21%
- Veröffentlicht 01.10.2026 09:28:33
- Zuletzt bearbeitet 01.10.2026 20:17:28
Missing authorization in module data retrieval allows unauthorized cross-group access to module history. Affects Pandora FMS from 777 onwards.
CVE-2026-64947
- EPSS 0.25%
- Veröffentlicht 01.10.2026 09:27:46
- Zuletzt bearbeitet 01.10.2026 20:17:28
A chained CSRF bypass and unrestricted file upload vulnerability in the Plugin File Manager allows an attacker to upload and execute arbitrary PHP code, resulting in Remote Code Execution. This issue affects Pandora FMS: from 777 onwards.
CVE-2026-64946
- EPSS 0.16%
- Veröffentlicht 01.10.2026 09:26:53
- Zuletzt bearbeitet 01.10.2026 15:17:30
A chained CSRF and unrestricted SVG file upload vulnerability in the File Manager module allows stored Cross-Site Scripting, enabling session cookie exfiltration and administrator account takeover. This issue affects Pandora FMS: from 777 onwards.
CVE-2026-34190
- EPSS 0.15%
- Veröffentlicht 01.10.2026 09:26:00
- Zuletzt bearbeitet 01.10.2026 16:17:42
Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of alert commands via sequential, unvalidated GET requests when an authenticated administrator visits a malicious page. This issue affects Pandora FMS: from 777 onwards.
CVE-2026-34189
- EPSS 0.21%
- Veröffentlicht 01.10.2026 09:24:43
- Zuletzt bearbeitet 01.10.2026 16:17:42
Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of event responses via a forged GET request when an authenticated administrator visits a malicious page. This issue affects Pandora FMS: from 777 onwards.
CVE-2026-34187
- EPSS 0.27%
- Veröffentlicht 12.05.2026 15:13:28
- Zuletzt bearbeitet 14.05.2026 13:05:09
Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via graph container parameter. This issue affects Pandora FMS: from 777 through 800
CVE-2026-30810
- EPSS 0.3%
- Veröffentlicht 12.05.2026 15:12:46
- Zuletzt bearbeitet 13.05.2026 14:37:34
Server-Side Request Forgery vulnerability allows Privilege Escalation via API Checker extension. This issue affects Pandora FMS: from 777 through 800