VYPR

Pandora FMS

by Pandora FMS

CVEs (4)

  • CVE-2026-64949HigOct 1, 2026
    risk 0.56cvss —epss —

    Incomplete extension blacklist in the File Manager module allows authenticated upload and execution of arbitrary .phar files. Affects Pandora FMS from 777 onwards.

  • CVE-2026-64950HigOct 1, 2026
    risk 0.55cvss —epss —

    Missing input validation and output encoding on the directory name parameter in File Manager's Create Directory allows stored XSS, executing without user interaction. Affects Pandora FMS from 777 onwards.

  • CVE-2026-64947HigOct 1, 2026
    risk 0.49cvss —epss —

    A chained CSRF bypass and unrestricted file upload vulnerability in the Plugin File Manager allows an attacker to upload and execute arbitrary PHP code, resulting in Remote Code Execution. This issue affects Pandora FMS: from 777 onwards.

  • CVE-2026-64946HigOct 1, 2026
    risk 0.48cvss —epss —

    A chained CSRF and unrestricted SVG file upload vulnerability in the File Manager module allows stored Cross-Site Scripting, enabling session cookie exfiltration and administrator account takeover. This issue affects Pandora FMS: from 777 onwards.