CVE-2026-30812: Stored Cross-Site Scripting in Event Comments via Filter Bypass
Published Apr 13, 2026
·Updated
Improper Neutralization of Input During Web Page Generation vulnerability allows Stored Cross-Site Scripting via event comments. This issue affects Pandora FMS: from 777 through 800
Affected Software
2 affected components
Pandora FMS Pandora FMS>=777<=800
Artica Pandora FMS>=777<800.1
Remediation
Information
Fixed in v800.1 and v801 Pandora FMS versions
Event History
Apr 13, 2026
CVE Published
via MITRE·03:48 PM
Data Sourced
via MITRE·03:48 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-30812?
CVE-2026-30812 is classified as a moderate severity vulnerability due to its impact on the security of event comments.
2
How can I fix CVE-2026-30812?
To mitigate CVE-2026-30812, upgrade Pandora FMS to a version higher than 800 which addresses the filter bypass issue.
3
What type of vulnerability is CVE-2026-30812?
CVE-2026-30812 is a Stored Cross-Site Scripting vulnerability that affects event comments.
4
Which versions of Pandora FMS are affected by CVE-2026-30812?
CVE-2026-30812 affects Pandora FMS versions from 777 to 800.
5
What can an attacker do with CVE-2026-30812?
An attacker leveraging CVE-2026-30812 can execute arbitrary JavaScript in the context of other users' browsers through event comments.