Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pandora FMS

First CVE: Nov 19, 2014Active for: 12 yearsTotal CVEs: 83
57.7
VTI Score
TOP TARGET

Pandora FMS is a monitoring and management platform that occupies a prominent position in enterprise infrastructure oversight, despite a narrow product footprint centered on its core Pandora FMS and Artica variants. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a strong tendency to acquire public exploit code, reflecting the platform's network-exposed architecture and reliance on web interfaces for administration and data collection. The exposure recurs persistently across web-application and file-handling weakness classes—cross-site scripting, CSRF, unrestricted file uploads, path traversal, and SQL injection—that are characteristic of large web-based management consoles where input validation and access boundaries must span complex attack surfaces. Defenders should prioritize patching this vendor's advisories and restrict network access to Pandora FMS consoles, since the recurring application-layer flaws and public exploit availability create material risk in organizations relying on the platform for operational visibility. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
83
Total CVEs
More Total CVEs than 99% of tracked vendors
2.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Pandora FMS over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 19, 2014
11 years ago
Most Recent CVE
May 12, 2026
73 days ago

Self-Reporting Analysis

Of all the CVEs published by Pandora FMS as a CNA, 89.7% affect products that Pandora FMS develops as a vendor.

89.7%
10.3%
Self-reported: 52 (89.7%)
Third-party: 6 (10.3%)

Of all the CVEs published that affect products developed by Pandora FMS, 62.7% are self-published by Pandora FMS as a CNA.

62.7%
37.3%
Self-published: 52 (62.7%)
Other CNAs: 31 (37.3%)

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (83 CVEs).

83 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-11320CRITICAL
Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication mechanism. This issue affects Pandora FMS: from 700 through <=
Nov 21, 20249.890NOYES
CVE-2020-13851HIGH
Artica Pandora FMS 7.44 allows remote command execution via the events feature.
Jun 11, 20208.886NOYES
CVE-2024-12971HIGH
Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection.This issue affects Pandora FMS from 700 to 777.6
Mar 17, 20258.873NOYES
CVE-2025-5306CRITICAL
Improper Neutralization of Special Elements in the Netflow directory field may allow OS command injection. This issue affects Pandora FMS 774 through 778
Jun 27, 20259.854NOYES
CVE-2025-34088HIGH
An authenticated remote code execution vulnerability exists in Pandora FMS version 7.0NG and earlier. The net_tools.php functionality allows authenticated users to execute arbitrar
Jul 3, 20258.842NOYES
CVE-2020-11749CRITICAL
Pandora FMS 7.0 NG <= 746 suffers from Multiple XSS vulnerabilities in different browser views. A network administrator scanning a SNMP device can trigger a Cross Site Scripting (X
Jul 13, 20209.042NOYES
CVE-2020-13855HIGH
Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Repository Manager feature.
Jun 11, 20207.237NONO
CVE-2020-13852HIGH
Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Manager feature.
Jun 11, 20207.237NONO
CVE-2023-44088HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows SQL Injection. Arbitrary SQL queries were allowed to
Dec 29, 20238.834NOYES
CVE-2026-34187CRITICAL
Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via graph container parameter. This issue affects Pandora FMS: from 777 throug
May 12, 20269.831NONO
View all 83 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products83 CVEs
42%
37%
19%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (1.2%)
Network81 (97.6%)
Unknown1 (1.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low81 (97.6%)
High1 (1.2%)
Unknown1 (1.2%)
User Interaction
None45 (54.2%)
Unknown1 (1.2%)
Required37 (44.6%)
Privileges Required
Low31 (37.3%)
High10 (12.0%)
None41 (49.4%)
Unknown1 (1.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (83 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
5 CVEs
6.0% of CVEs· 98th percentile
Nuclei
2 CVEs
2.4% of CVEs· 95th percentile
ExploitDB
2 CVEs
2.4% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pandora FMS.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pandora FMS — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pandora FMS's Products

View all 4 CNAs →

Top CWEs