Pandora FMS is a monitoring and management platform that occupies a prominent position in enterprise infrastructure oversight, despite a narrow product footprint centered on its core Pandora FMS and Artica variants. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a strong tendency to acquire public exploit code, reflecting the platform's network-exposed architecture and reliance on web interfaces for administration and data collection. The exposure recurs persistently across web-application and file-handling weakness classes—cross-site scripting, CSRF, unrestricted file uploads, path traversal, and SQL injection—that are characteristic of large web-based management consoles where input validation and access boundaries must span complex attack surfaces. Defenders should prioritize patching this vendor's advisories and restrict network access to Pandora FMS consoles, since the recurring application-layer flaws and public exploit availability create material risk in organizations relying on the platform for operational visibility. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pandora FMS over time
Of all the CVEs published by Pandora FMS as a CNA, 89.7% affect products that Pandora FMS develops as a vendor.
Of all the CVEs published that affect products developed by Pandora FMS, 62.7% are self-published by Pandora FMS as a CNA.
Signals from CVEs in this vendor scope (83 CVEs).
83 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-11320CRITICAL Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication mechanism. This issue affects Pandora FMS: from 700 through <= | Nov 21, 2024 | 9.8 | 90 | NO | YES |
CVE-2020-13851HIGH Artica Pandora FMS 7.44 allows remote command execution via the events feature. | Jun 11, 2020 | 8.8 | 86 | NO | YES |
CVE-2024-12971HIGH Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection.This issue affects Pandora FMS from 700 to 777.6 | Mar 17, 2025 | 8.8 | 73 | NO | YES |
CVE-2025-5306CRITICAL Improper Neutralization of Special Elements in the Netflow directory field may allow OS command injection. This issue affects Pandora FMS 774 through 778 | Jun 27, 2025 | 9.8 | 54 | NO | YES |
CVE-2025-34088HIGH An authenticated remote code execution vulnerability exists in Pandora FMS version 7.0NG and earlier. The net_tools.php functionality allows authenticated users to execute arbitrar | Jul 3, 2025 | 8.8 | 42 | NO | YES |
CVE-2020-11749CRITICAL Pandora FMS 7.0 NG <= 746 suffers from Multiple XSS vulnerabilities in different browser views. A network administrator scanning a SNMP device can trigger a Cross Site Scripting (X | Jul 13, 2020 | 9.0 | 42 | NO | YES |
CVE-2020-13855HIGH Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Repository Manager feature. | Jun 11, 2020 | 7.2 | 37 | NO | NO |
CVE-2020-13852HIGH Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Manager feature. | Jun 11, 2020 | 7.2 | 37 | NO | NO |
CVE-2023-44088HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows SQL Injection. Arbitrary SQL queries were allowed to | Dec 29, 2023 | 8.8 | 34 | NO | YES |
CVE-2026-34187CRITICAL Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via graph container parameter. This issue affects Pandora FMS: from 777 throug | May 12, 2026 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (83 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pandora FMS.
Media articles that mention a CVE ID that affects a product developed by Pandora FMS — matched by CVE ID, not by vendor name.