{"schema_version":1,"title":"Artica Pandora FMS vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 13 vulnerabilities in Artica Pandora FMS: 0 in the last 7 days and 0 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-34187, was published on 12 May 2026.","url":"https://junglewise.ai/threats/technologies/pandora-fms","json_url":"https://junglewise.ai/threats/technologies/pandora-fms.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/pandora-fms","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":9,"all_time":13,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":13},"latest":[{"cve":"CVE-2026-34187","cvss":7.6,"slug":"cve-2026-34187-artica-pandora-fms-sql-injection-in-graph-container-parameter","title":"Artica Pandora FMS SQL injection in graph container parameter","severity":"info","exploited":false,"published_at":"2026-05-12T16:16:14.8+00:00","url":"https://junglewise.ai/threats/cve-2026-34187-artica-pandora-fms-sql-injection-in-graph-container-parameter"},{"cve":"CVE-2026-30810","cvss":8.8,"slug":"cve-2026-30810-artica-pandora-fms-ssrf-and-privilege-escalation-in-api-checker","title":"Artica Pandora FMS SSRF and privilege escalation in API Checker extension","severity":"high","exploited":false,"published_at":"2026-05-12T16:16:13.13+00:00","url":"https://junglewise.ai/threats/cve-2026-30810-artica-pandora-fms-ssrf-and-privilege-escalation-in-api-checker"},{"cve":"CVE-2026-30808","cvss":8.1,"slug":"cve-2026-30808-artica-pandora-fms-session-fixation","title":"Artica Pandora FMS session fixation","severity":"high","exploited":false,"published_at":"2026-05-12T16:16:12.973+00:00","url":"https://junglewise.ai/threats/cve-2026-30808-artica-pandora-fms-session-fixation"},{"cve":"CVE-2026-30807","cvss":8.8,"slug":"cve-2026-30807-artica-pandora-fms-cross-site-request-forgery","title":"Artica Pandora FMS Cross-Site Request Forgery","severity":"high","exploited":false,"published_at":"2026-05-12T16:16:12.833+00:00","url":"https://junglewise.ai/threats/cve-2026-30807-artica-pandora-fms-cross-site-request-forgery"},{"cve":"CVE-2026-30805","cvss":9.1,"slug":"cve-2026-30805-artica-pandora-fms-authentication-bypass-in-api","title":"Artica Pandora FMS authentication bypass in API","severity":"critical","exploited":false,"published_at":"2026-05-12T16:16:12.683+00:00","url":"https://junglewise.ai/threats/cve-2026-30805-artica-pandora-fms-authentication-bypass-in-api"},{"cve":"CVE-2026-34188","cvss":7.2,"slug":"cve-2026-34188-artica-pandora-fms-os-command-injection-in-event-response","title":"Artica Pandora FMS OS command injection in Event Response","severity":"high","exploited":false,"published_at":"2026-04-13T16:16:27.487+00:00","url":"https://junglewise.ai/threats/cve-2026-34188-artica-pandora-fms-os-command-injection-in-event-response"},{"cve":"CVE-2026-34186","cvss":8.8,"slug":"cve-2026-34186-artica-pandora-fms-sql-injection-in-custom-fields","title":"Artica Pandora FMS SQL injection in custom fields","severity":"high","exploited":false,"published_at":"2026-04-13T16:16:27.343+00:00","url":"https://junglewise.ai/threats/cve-2026-34186-artica-pandora-fms-sql-injection-in-custom-fields"},{"cve":"CVE-2026-30813","cvss":8.8,"slug":"cve-2026-30813-artica-pandora-fms-sql-injection-in-module-search","title":"Artica Pandora FMS SQL injection in module search","severity":"high","exploited":false,"published_at":"2026-04-13T16:16:26.303+00:00","url":"https://junglewise.ai/threats/cve-2026-30813-artica-pandora-fms-sql-injection-in-module-search"},{"cve":"CVE-2026-30812","cvss":5.4,"slug":"cve-2026-30812-artica-pandora-fms-stored-xss-in-event-comments","title":"Artica Pandora FMS Stored XSS in event comments","severity":"medium","exploited":false,"published_at":"2026-04-13T16:16:26.147+00:00","url":"https://junglewise.ai/threats/cve-2026-30812-artica-pandora-fms-stored-xss-in-event-comments"},{"cve":"CVE-2026-30811","cvss":6.5,"slug":"cve-2026-30811-artica-pandora-fms-sensitive-information-exposure-in","title":"Artica Pandora FMS Sensitive Information Exposure in configuration endpoint","severity":"medium","exploited":false,"published_at":"2026-04-13T16:16:25.993+00:00","url":"https://junglewise.ai/threats/cve-2026-30811-artica-pandora-fms-sensitive-information-exposure-in"},{"cve":"CVE-2026-30809","cvss":8.8,"slug":"cve-2026-30809-artica-pandora-fms-os-command-injection-in-webservermoduledebug","title":"Artica Pandora FMS OS command injection in WebServerModuleDebug","severity":"high","exploited":false,"published_at":"2026-04-13T16:16:25.853+00:00","url":"https://junglewise.ai/threats/cve-2026-30809-artica-pandora-fms-os-command-injection-in-webservermoduledebug"},{"cve":"CVE-2026-30806","cvss":8.8,"slug":"cve-2026-30806-artica-pandora-fms-os-command-injection-in-network-report","title":"Artica Pandora FMS OS command injection in Network Report","severity":"high","exploited":false,"published_at":"2026-04-13T16:16:25.68+00:00","url":"https://junglewise.ai/threats/cve-2026-30806-artica-pandora-fms-os-command-injection-in-network-report"},{"cve":"CVE-2026-30804","cvss":7.2,"slug":"cve-2026-30804-artica-pandora-fms-remote-code-execution-via-unrestricted-file","title":"Artica Pandora FMS remote code execution via unrestricted file upload","severity":"high","exploited":false,"published_at":"2026-04-13T16:16:25.487+00:00","url":"https://junglewise.ai/threats/cve-2026-30804-artica-pandora-fms-remote-code-execution-via-unrestricted-file"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"Artica Pandora FMS","slug":"pandora-fms","vendor":{"name":"Artica","slug":"artica","url":"https://junglewise.ai/threats/vendors/artica"},"aliases":[],"category":"monitoring-software","homepage":"https://pandorafms.com/","repo_url":"https://github.com/pandorafms/pandorafms","description":"Pandora FMS is an open-source monitoring solution for IT infrastructure management, including networks, servers, and applications.","url":"https://junglewise.ai/threats/technologies/pandora-fms"},"most_severe":[{"cve":"CVE-2026-30805","cvss":9.1,"slug":"cve-2026-30805-artica-pandora-fms-authentication-bypass-in-api","title":"Artica Pandora FMS authentication bypass in API","severity":"critical","exploited":false,"published_at":"2026-05-12T16:16:12.683+00:00","url":"https://junglewise.ai/threats/cve-2026-30805-artica-pandora-fms-authentication-bypass-in-api"},{"cve":"CVE-2026-30810","cvss":8.8,"slug":"cve-2026-30810-artica-pandora-fms-ssrf-and-privilege-escalation-in-api-checker","title":"Artica Pandora FMS SSRF and privilege escalation in API Checker extension","severity":"high","exploited":false,"published_at":"2026-05-12T16:16:13.13+00:00","url":"https://junglewise.ai/threats/cve-2026-30810-artica-pandora-fms-ssrf-and-privilege-escalation-in-api-checker"},{"cve":"CVE-2026-30807","cvss":8.8,"slug":"cve-2026-30807-artica-pandora-fms-cross-site-request-forgery","title":"Artica Pandora FMS Cross-Site Request Forgery","severity":"high","exploited":false,"published_at":"2026-05-12T16:16:12.833+00:00","url":"https://junglewise.ai/threats/cve-2026-30807-artica-pandora-fms-cross-site-request-forgery"},{"cve":"CVE-2026-34186","cvss":8.8,"slug":"cve-2026-34186-artica-pandora-fms-sql-injection-in-custom-fields","title":"Artica Pandora FMS SQL injection in custom fields","severity":"high","exploited":false,"published_at":"2026-04-13T16:16:27.343+00:00","url":"https://junglewise.ai/threats/cve-2026-34186-artica-pandora-fms-sql-injection-in-custom-fields"},{"cve":"CVE-2026-30813","cvss":8.8,"slug":"cve-2026-30813-artica-pandora-fms-sql-injection-in-module-search","title":"Artica Pandora FMS SQL injection in module search","severity":"high","exploited":false,"published_at":"2026-04-13T16:16:26.303+00:00","url":"https://junglewise.ai/threats/cve-2026-30813-artica-pandora-fms-sql-injection-in-module-search"},{"cve":"CVE-2026-30809","cvss":8.8,"slug":"cve-2026-30809-artica-pandora-fms-os-command-injection-in-webservermoduledebug","title":"Artica Pandora FMS OS command injection in WebServerModuleDebug","severity":"high","exploited":false,"published_at":"2026-04-13T16:16:25.853+00:00","url":"https://junglewise.ai/threats/cve-2026-30809-artica-pandora-fms-os-command-injection-in-webservermoduledebug"},{"cve":"CVE-2026-30806","cvss":8.8,"slug":"cve-2026-30806-artica-pandora-fms-os-command-injection-in-network-report","title":"Artica Pandora FMS OS command injection in Network Report","severity":"high","exploited":false,"published_at":"2026-04-13T16:16:25.68+00:00","url":"https://junglewise.ai/threats/cve-2026-30806-artica-pandora-fms-os-command-injection-in-network-report"},{"cve":"CVE-2026-30808","cvss":8.1,"slug":"cve-2026-30808-artica-pandora-fms-session-fixation","title":"Artica Pandora FMS session fixation","severity":"high","exploited":false,"published_at":"2026-05-12T16:16:12.973+00:00","url":"https://junglewise.ai/threats/cve-2026-30808-artica-pandora-fms-session-fixation"},{"cve":"CVE-2026-34188","cvss":7.2,"slug":"cve-2026-34188-artica-pandora-fms-os-command-injection-in-event-response","title":"Artica Pandora FMS OS command injection in Event Response","severity":"high","exploited":false,"published_at":"2026-04-13T16:16:27.487+00:00","url":"https://junglewise.ai/threats/cve-2026-34188-artica-pandora-fms-os-command-injection-in-event-response"},{"cve":"CVE-2026-30804","cvss":7.2,"slug":"cve-2026-30804-artica-pandora-fms-remote-code-execution-via-unrestricted-file","title":"Artica Pandora FMS remote code execution via unrestricted file upload","severity":"high","exploited":false,"published_at":"2026-04-13T16:16:25.487+00:00","url":"https://junglewise.ai/threats/cve-2026-30804-artica-pandora-fms-remote-code-execution-via-unrestricted-file"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}