📦 Pandora Fms

by Pandorafms

🔍 What is Pandora Fms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-11320

CRITICAL CVSS 9.8 Nov 21, 2024

This vulnerability allows attackers to execute arbitrary commands on Pandora FMS servers by exploiting a command injection flaw in the LDAP authentication mechanism. Attackers can gain full control of...

CVE-2021-34074

CRITICAL CVSS 9.8 Jun 25, 2021

PandoraFMS versions up to 7.54 contain an arbitrary file upload vulnerability in the File Manager component. Attackers can bypass built-in protections using relative paths to upload malicious files, l...

CVE-2025-34088

HIGH CVSS 8.8 Jul 3, 2025

This vulnerability allows authenticated users in Pandora FMS to execute arbitrary operating system commands through the net_tools.php functionality. Attackers can inject malicious commands via the sel...

CVE-2024-35308

HIGH CVSS 8.8 Oct 22, 2024

This vulnerability allows authenticated attackers to read arbitrary files on Pandora FMS servers through the plugin edition feature. It affects Pandora FMS versions 700 through 777.2, potentially expo...

CVE-2023-41815

HIGH CVSS 7.5 Dec 29, 2023

This CVE describes a cross-site scripting (XSS) vulnerability in Pandora FMS that allows attackers to inject malicious scripts into the File Manager section. When exploited, this could enable session ...

CVE-2022-47372

HIGH CVSS 7.6 Feb 15, 2023

This stored cross-site scripting vulnerability in Pandora FMS allows attackers to inject malicious scripts into the Create event section. When users view the compromised page, the scripts execute in t...