CVE-2026-30812: low-severity vulnerability in Pandora FMS
Stored Cross-Site Scripting in Event Comments via Filter Bypass
Published
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 2.1epss 0.2%
exploitation probability
0.2%top 87% of all CVEs
observed exploitation
nono source reports it
Improper Neutralization of Input During Web Page Generation vulnerability allows Stored Cross-Site Scripting via event comments. This issue affects Pandora FMS: from 777 through 800
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/S:N/AU:N/R:A/V:D/RE:L/U:Amber
Affected products
Pandora FMS · Pandora FMSRelated CVEs — Pandora FMS
In the same product, most dangerous first.
CVE-2024-11320MEDIUMCommand Injection leading to RCE via LDAP MisconfigurationEPSS 91.2%CVE-2024-12971HIGHQuickShell Authenticated Command InjectionEPSS 61.5%CVE-2025-5306HIGHCommand Injection in Netflow pathEPSS 35.7%CVE-2026-34188HIGHOS Command Injection in Event Response ExecutionEPSS 1.7%CVE-2026-30809HIGHOS Command Injection in WebServerModuleDebug via Blacklist Bypass leads to Remote Code ExecutionEPSS 1.6%CVE-2026-30806HIGHOS Command Injection in Network Report leads to Remote Code ExecutionEPSS 1.6%