CVE-2019-19968: Pandorafms Pandora Fms

Medium severity, CVSS 5.4. EPSS: 0.8% chance of exploitation in the next 30 days.

PandoraFMS 742 suffers from multiple XSS vulnerabilities, affecting the Agent Management, Report Builder, and Graph Builder components. An authenticated user can inject dangerous content into a data store that is later read and included in dynamic content.

Affected products

Published 2020-02-04. Last modified 2026-06-17.