VendorsPandora FMSpandora_fmsany version
Vulnerabilities

Pandora FMS 7.0 NG 723 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

37CVEs
CVE-2024-11320
Command Injection leading to RCE via LDAP Misconfiguration
Published 2024-11-21 · Analyzed
9.8EPSS 0.910
CVE-2021-34074
PandoraFMS <=7.54 allows arbitrary file upload, it leading to remote command execution via the File Manager. To bypass the built-in protection, a relative path is used in the requests.
Published 2021-06-25 · Modified
9.8EPSS 0.075
CVE-2022-43979
Path Traversal leading to Local File Inclusion
Published 2023-01-27 · Modified
9.8EPSS 0.008
CVE-2023-2807
Authentication bypass in password reset process
Published 2023-06-13 · Modified
9.8EPSS 0.006
CVE-2020-11749
Pandora FMS 7.0 NG <= 746 suffers from Multiple XSS vulnerabilities in different browser views. A network administrator scanning a SNMP device can trigger a Cross Site Scripting (XSS), which can run arbitrary code to allow Remote Code Execution as root or apache2.
Published 2020-07-13 · Modified
9.01 PoCEPSS 0.162
CVE-2025-34088
Pandora FMS Authenticated Remote Code Execution via Ping Module
Published 2025-07-03 · Analyzed
8.8EPSS 0.073
CVE-2022-0507
Vulnerability: Authenticated SQL Injection in API
Published 2022-03-09 · Modified
8.8EPSS 0.012
CVE-2023-44088
SQL Injection in Visual Console
Published 2023-12-29 · Modified
8.81 PoCEPSS 0.007
CVE-2022-26310
Improper Authorization in User Management to Vertical Privilege Escalation
Published 2022-08-01 · Modified
8.8EPSS 0.007
CVE-2024-35308
Post-auth Arbitrary File Read in the Server Plugins Section
Published 2024-10-22 · Analyzed
8.8EPSS 0.006
CVE-2024-9987
SQL Injection in CSV Module Data Collection
Published 2024-10-22 · Analyzed
8.8EPSS 0.004
CVE-2022-26309
Cross-Site Request en Bulk operation (User operation)
Published 2022-08-01 · Modified
8.8EPSS 0.003
CVE-2019-13035
Artica Pandora FMS 7.0 NG before 735 suffers from local privilege escalation due to improper permissions on C:\PandoraFMS and its sub-folders, allowing standard users to create new files. Moreover, the Apache service httpd.exe will try to execute cmd.exe from C:\PandoraFMS (the current directory) as NT AUTHORITY\SYSTEM upon web requests to the portal. This will effectively allow non-privileged users to escalate privileges to NT AUTHORITY\SYSTEM.
Published 2019-06-29 · Modified
7.8EPSS 0.004
CVE-2022-47372
Stored cross-site scripting vulnerability in create event section
Published 2023-02-15 · Modified
7.6EPSS 0.002
CVE-2023-41815
XSS in File manager
Published 2023-12-29 · Modified
7.5EPSS 0.003
CVE-2022-1648
Relative Path Traversal to Remote Code Execution in File Manager
Published 2022-07-26 · Modified
7.2EPSS 0.013
CVE-2023-24517
Remote Code Execution via Unrestricted File Upload
Published 2023-08-22 · Modified
7.2EPSS 0.010
CVE-2023-24518
Disabling the administrator's account through cross-site request forgery
Published 2023-10-03 · Modified
7.1EPSS 0.002
CVE-2023-0828
Stored Cross Site Scripting in syslog section
Published 2023-10-03 · Modified
6.7EPSS 0.003
CVE-2023-24515
Server side request forgery in api checker
Published 2023-08-22 · Modified
6.5EPSS 0.004
CVE-2022-47373
Reflected Cross Site Scripting in Search Functionality of Module Library
Published 2023-02-15 · Modified
6.4EPSS 0.003
CVE-2023-24514
Stored Cross Site Scripting Vulnerability in Visual Console Module
Published 2023-08-22 · Modified
6.3EPSS 0.004
CVE-2021-46676
Vulnerability XSS in Transaction Map name field
Published 2022-08-05 · Modified
6.1EPSS 0.004
CVE-2021-46679
Vulnerability XSS in service elements
Published 2022-08-05 · Modified
6.1EPSS 0.004
CVE-2021-46677
Vulnerability XSS in Event filter name field
Published 2022-08-05 · Modified
6.1EPSS 0.004
CVE-2021-46678
Vulnerability XSS in service form name field
Published 2022-08-05 · Modified
6.1EPSS 0.004
CVE-2021-46680
Vulnerability XSS in module form name field
Published 2022-08-05 · Modified
6.1EPSS 0.004
CVE-2023-41813
User notification settings edition
Published 2023-12-29 · Modified
6.1EPSS 0.003
CVE-2023-41814
XSS Vulnerability Messages
Published 2023-12-29 · Modified
6.1EPSS 0.003
CVE-2023-44089
XSS in Visual Console
Published 2023-12-29 · Modified
6.1EPSS 0.003
CVE-2023-24516
Stored Cross Site Scripting - Special Days Module
Published 2023-08-22 · Modified
5.9EPSS 0.004
CVE-2022-43978
Limited Authentication bypass due to hardcoded secret
Published 2023-01-27 · Modified
5.6EPSS 0.003
CVE-2021-35501
PandoraFMS <=7.54 allows Stored XSS by placing a payload in the name field of a visual console. When a user or an administrator visits the console, the XSS payload will be executed.
Published 2021-06-25 · Modified
5.4EPSS 0.010
CVE-2022-26308
Improper Access Control in Configuration (Credential store)
Published 2022-08-01 · Modified
5.4EPSS 0.004
CVE-2022-43980
Cross-site scripting vulnerability in the network maps edit functionality
Published 2023-01-27 · Modified
5.4EPSS 0.003
CVE-2022-2032
Stored Cross Site-Scripting in File Manager
Published 2022-07-25 · Modified
4.8EPSS 0.004
CVE-2022-2059
Stored Cross Site-Scripting in Agent Manager
Published 2022-07-25 · Modified
4.8EPSS 0.004