pandora
pandora-analysis- Software type
- —
- Catalog vulnerabilities
- 5
Severity across 5 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 5 analyzed records
A short verification protects source data and prevents automated AI requests.
The GCVE catalog currently lists 5 vulnerability records affecting pandora.
Among the 5 records analyzed by CyStack, 4 are High or Critical and 0 appear in the CISA KEV catalog.
Compare the version you run with each vulnerability and the provider guidance below. The data only includes records analyzed so far.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan
| CVE | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-88069Path traversal in Pandora archive extractor allows arbitrary file writes outside the extraction directory in pandora analysis | Exploitation statusNot known exploited | FixYes | Published09/09/2026 | SeverityCritical |
CVE-2026-75531Stored Cross-Site Scripting in URL Observables via Lookyloo Submission Handler in Pandora | Exploitation statusNot known exploited | FixYes | Published08/17/2026 | SeverityHigh |
CVE-2026-75529Stored Cross-Site Scripting via MIME-Type Confusion in PDF Downloads of Pandora | Exploitation statusNot known exploited | FixYes | Published08/17/2026 | SeverityMedium |
CVE-2026-74767Unbounded DAA Decompression in Pandora Allows Denial of Service via Decompression Bomb | Exploitation statusNot known exploited | FixYes | Published08/15/2026 | SeverityHigh |
CVE-2026-74764Path Traversal in TAR Archive Extraction Allows Arbitrary File Write in Pandora | Exploitation statusNot known exploited | FixYes | Published08/15/2026 | SeverityCritical |