Known Vulnerabilities for Monstra Cms by Monstra
Listed below are 8 of the newest known vulnerabilities associated with "Monstra Cms" by "Monstra".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-23697 json | Cross Site Scripting vulnerabilty in Monstra CMS 3.0.4 via the page feature in admin/index.php. | 5.4 - MEDIUM | 2021-07-06 | 2021-07-08 |
| CVE-2020-23219 json | Monstra CMS 3.0.4 allows attackers to execute arbitrary code via a crafted payload entered into the "Snippet content" field u... | 8.8 - HIGH | 2021-07-01 | 2022-05-03 |
| CVE-2020-23205 json | A stored cross site scripting (XSS) vulnerability in Monstra CMS version 3.0.4 allows attackers to execute arbitrary web scri... | 5.4 - MEDIUM | 2021-07-01 | 2021-07-06 |
| CVE-2020-20691 json | An issue in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via bypassing the file extension fil... | 6.5 - MEDIUM | 2021-09-27 | 2021-10-08 |
| CVE-2020-13978 json | ** DISPUTED ** Monstra CMS 3.0.4 allows an attacker, who already has administrative access to modify .chunk.php files on the ... | 7.2 - HIGH | 2020-06-09 | 2023-11-07 |
| CVE-2018-19599 json | Monstra CMS 1.6 allows XSS via an uploaded SVG document to the admin/index.php?id=filesmanager&path=uploads/ URI. NOTE: this ... | 5.4 - MEDIUM | 2020-03-02 | 2020-06-24 |
| CVE-2018-11678 json | plugins/box/users/users.plugin.php in Monstra CMS 3.0.4 allows Login Rate Limiting Bypass via manipulation of the login_attem... | 9.8 - CRITICAL | 2018-06-05 | 2018-07-20 |
| CVE-2018-11227 json | Monstra CMS 3.0.4 and earlier has XSS via index.php. | 6.1 - MEDIUM | 2019-07-03 | 2019-07-08 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Monstra | Monstra Cms | 3.0.4 | |||
| Application | Monstra | Monstra Cms | 3.0.3 | |||
| Application | Monstra | Monstra Cms | 3.0.2 | |||
| Application | Monstra | Monstra Cms | 3.0.1 | |||
| Application | Monstra | Monstra Cms | 3.0.0 | |||
| Application | Monstra | Monstra Cms | 2.3.1 | |||
| Application | Monstra | Monstra Cms | 2.3.0 | |||
| Application | Monstra | Monstra Cms | 2.2.1 | |||
| Application | Monstra | Monstra Cms | 2.2.0 | |||
| Application | Monstra | Monstra Cms | 2.1.3 | |||
| Application | Monstra | Monstra Cms | 2.1.2 | |||
| Application | Monstra | Monstra Cms | 2.1.1 | |||
| Application | Monstra | Monstra Cms | 2.1.0 | |||
| Application | Monstra | Monstra Cms | 2.0.1 | |||
| Application | Monstra | Monstra Cms | 2.0.0 | |||
| Application | Monstra | Monstra Cms | 1.6 | |||
| Application | Monstra | Monstra Cms | 1.3.1 | |||
| Application | Monstra | Monstra Cms | 1.3.0 | |||
| Application | Monstra | Monstra Cms | 1.2.1 | |||
| Application | Monstra | Monstra Cms | 1.2.0 |