VendorsPandora FMSpandora_fmsall versions
Vulnerabilities

Pandora FMS 7.0 NG 723

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

46CVEs
CVE-2021-35501
PandoraFMS <=7.54 allows Stored XSS by placing a payload in the name field of a visual console. When a user or an administrator visits the console, the XSS payload will be executed.
Published 2021-06-25 · Modified
5.4EPSS 0.010
CVE-2019-19968
PandoraFMS 742 suffers from multiple XSS vulnerabilities, affecting the Agent Management, Report Builder, and Graph Builder components. An authenticated user can inject dangerous content into a data store that is later read and included in dynamic content.
Published 2020-02-04 · Modified
5.4EPSS 0.008
CVE-2022-26308
Improper Access Control in Configuration (Credential store)
Published 2022-08-01 · Modified
5.4EPSS 0.004
CVE-2022-43980
Cross-site scripting vulnerability in the network maps edit functionality
Published 2023-01-27 · Modified
5.4EPSS 0.003
CVE-2022-2032
Stored Cross Site-Scripting in File Manager
Published 2022-07-25 · Modified
4.8EPSS 0.004
CVE-2022-2059
Stored Cross Site-Scripting in Agent Manager
Published 2022-07-25 · Modified
4.8EPSS 0.004
← Prev2 / 2