CVE-2024-35308: Pandorafms Pandora Fms

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

A post-authentication arbitrary file read vulnerability within the server plugins section in plugin edition feature. This issue affects Pandora FMS: from 700 through <777.3.

Affected products

  • Pandorafms Pandora Fms: from 700, before 777.3 (fixed in 777.3)

Published 2024-10-22. Last modified 2026-06-17.