VYPR

File Manager

by Pandora FMS

CVEs (3)

  • CVE-2026-64949HigOct 1, 2026
    risk 0.56cvss —epss —

    Incomplete extension blacklist in the File Manager module allows authenticated upload and execution of arbitrary .phar files. Affects Pandora FMS from 777 onwards.

  • CVE-2026-64950HigOct 1, 2026
    risk 0.55cvss —epss —

    Missing input validation and output encoding on the directory name parameter in File Manager's Create Directory allows stored XSS, executing without user interaction. Affects Pandora FMS from 777 onwards.

  • CVE-2026-64946HigOct 1, 2026
    risk 0.48cvss —epss —

    A chained CSRF and unrestricted SVG file upload vulnerability in the File Manager module allows stored Cross-Site Scripting, enabling session cookie exfiltration and administrator account takeover. This issue affects Pandora FMS: from 777 onwards.