CVE-2022-47372: Pandorafms Pandora Fms

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Stored cross-site scripting vulnerability in the Create event section in Pandora FMS Console v766 and lower. An attacker typically exploits this vulnerability by injecting XSS payloads on popular pages of a site or passing a link to a victim, tricking them into viewing the page that contains the stored XSS payload.

Affected products

Published 2023-02-15. Last modified 2026-06-17.