Monstra / Monstra Cms
12 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-69906 | Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin. The application relies on blacklist-based file extension valida… | HIGH | 8.8 | Feb 5, 2026 |
| CVE-2024-36773 | A cross-site scripting (XSS) vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into… | MEDIUM | 4.8 | Jun 7, 2024 |
| CVE-2024-36775 | A cross-site scripting (XSS) vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into… | MEDIUM | 5.4 | Jun 6, 2024 |
| CVE-2024-36774 | An arbitrary file upload vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary code via uploading a crafted PHP file. | HIGH | 8.0 | Jun 6, 2024 |
| CVE-2020-20691 | An issue in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via bypassing the file extension filter and uploading crafted HTML fil… | MEDIUM | 6.5 | Sep 27, 2021 |
| CVE-2020-23697 | Cross Site Scripting vulnerabilty in Monstra CMS 3.0.4 via the page feature in admin/index.php. | MEDIUM | 5.4 | Jul 6, 2021 |
| CVE-2020-23219 | Monstra CMS 3.0.4 allows attackers to execute arbitrary code via a crafted payload entered into the "Snippet content" field under the "Edit Snippet" module. | HIGH | 8.8 | Jul 1, 2021 |
| CVE-2020-23205 | A stored cross site scripting (XSS) vulnerability in Monstra CMS version 3.0.4 allows attackers to execute arbitrary web scripts or HTML via crafted a payload… | MEDIUM | 5.4 | Jul 1, 2021 |
| CVE-2020-13978 | Monstra CMS 3.0.4 allows an attacker, who already has administrative access to modify .chunk.php files on the Edit Chunk screen, to execute arbitrary OS comman… | HIGH | 7.2 | Jun 9, 2020 |
| CVE-2018-19599 | Monstra CMS 1.6 allows XSS via an uploaded SVG document to the admin/index.php?id=filesmanager&path=uploads/ URI. NOTE: this is a discontinued product. | MEDIUM | 5.4 | Mar 2, 2020 |
| CVE-2018-11227 | Monstra CMS 3.0.4 and earlier has XSS via index.php. | MEDIUM | 6.1 | Jul 3, 2019 |
| CVE-2018-11678 | plugins/box/users/users.plugin.php in Monstra CMS 3.0.4 allows Login Rate Limiting Bypass via manipulation of the login_attempts cookie. | CRITICAL | 9.8 | Jun 5, 2018 |
Showing 1 to 12 of 12 CVEs