Pandora Fms
115 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Pandora Fms, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
Pandora Fms CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 2 |
| 2024-11 | 1 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 2 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 1 |
| 2025-07 | 3 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 8 |
| 2026-05 | 5 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 115 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical19
- High43
- Medium45
- Low6
Latest CVEs
The 15 most recently published vulnerabilities affecting Pandora Fms.
- CVE-2026-34187SQL Injection in Graph Container Parameter9.8
- CVE-2026-30810Server-Side Request Forgery in API Checker leads to Privilege Escalation8.8
- CVE-2026-30808Session Fixation in Authentication leads to Session Hijacking8.1
- CVE-2026-30807Cross-Site Request Forgery on Extension Pages8.8
- CVE-2026-30805Insecure Default Initialization in API Authentication leads to Authentication Bypass9.1
- CVE-2026-34188OS Command Injection in Event Response Execution7.2
- CVE-2026-34186SQL Injection in Custom Fields leads to Database Compromise8.8
- CVE-2026-30813SQL Injection in Module Search leads to Database Compromise8.8
- CVE-2026-30812Stored Cross-Site Scripting in Event Comments via Filter Bypass5.4
- CVE-2026-30811Missing Authorization in Configuration Ajax Endpoint leads to Information Disclosure6.5
- CVE-2026-30809OS Command Injection in WebServerModuleDebug via Blacklist Bypass leads to Remote Code Execution8.8
- CVE-2026-30806OS Command Injection in Network Report leads to Remote Code Execution8.8
- CVE-2026-30804Unrestricted File Upload in Extension Uploader leads to Remote Code Execution7.2
- CVE-2014-125124Pandora FMS <= 5.0RC1 Anyterm Unauthenticated Command Injection—
- CVE-2014-125115Pandora FMS ≤ 5.0 SP2 Default Credential SQL Injection RCE—
Product grouping is registry-driven, with AI assist and human review. How it works