HIGH 8.4 NVD
CVE-2026-64950
Missing input validation and output encoding on the directory name parameter in File Manager's Create Directory allows stored XSS, executing without user intera
Missing input validation and output encoding on the directory name parameter in File Manager's Create Directory allows stored XSS, executing without user interaction. Affects Pandora FMS from 777 onwards.
References
This high severity vulnerability with a CVSS score of 8.4 was published on 2026-10-01 via NVD.
vulnfeed aggregates 12641 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.