📦 Monstra

by Monstra

🔍 What is Monstra?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-40940

CRITICAL CVSS 9.8 Jun 15, 2022

Monstra CMS 3.0.4 has an unrestricted file upload vulnerability due to insufficient filtering of PHP file extensions. Attackers can upload malicious PHP files to execute arbitrary code on the server. ...

CVE-2020-25414

CRITICAL CVSS 9.8 Jun 17, 2021

This vulnerability allows remote attackers to execute arbitrary PHP code through a local file inclusion flaw in Monstra CMS's captcha function. Attackers can potentially take full control of affected ...

CVE-2024-36773

MEDIUM CVSS 4.8 Jun 7, 2024

This cross-site scripting (XSS) vulnerability in Monstra CMS allows attackers to inject malicious scripts into the Themes parameter, which could lead to session hijacking, defacement, or credential th...

CVE-2024-36775

MEDIUM CVSS 5.4 Jun 6, 2024

This cross-site scripting (XSS) vulnerability in Monstra CMS v3.0.4 allows attackers to inject malicious scripts into the 'About Me' field of user profiles. When other users view these profiles, the s...