Known Vulnerabilities for products from Monstra
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Monstra".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-40940 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 9.8 - CRITICAL | 2022-06-15 | 2022-06-24 |
| CVE-2021-36548 json | A remote code execution (RCE) vulnerability in the component /admin/index.php?id=themes&action=edit_template&filename=blog of... | 9.8 - CRITICAL | 2021-10-28 | 2021-11-02 |
| CVE-2020-25414 json | A local file inclusion vulnerability was discovered in the captcha function in Monstra 3.0.4 which allows remote attackers to... | 9.8 - CRITICAL | 2021-06-17 | 2022-07-12 |
| CVE-2020-23697 json | Cross Site Scripting vulnerabilty in Monstra CMS 3.0.4 via the page feature in admin/index.php. | 5.4 - MEDIUM | 2021-07-06 | 2021-07-08 |
| CVE-2020-23219 json | Monstra CMS 3.0.4 allows attackers to execute arbitrary code via a crafted payload entered into the "Snippet content" field u... | 8.8 - HIGH | 2021-07-01 | 2022-05-03 |
| CVE-2020-23205 json | A stored cross site scripting (XSS) vulnerability in Monstra CMS version 3.0.4 allows attackers to execute arbitrary web scri... | 5.4 - MEDIUM | 2021-07-01 | 2021-07-06 |
| CVE-2020-20691 json | An issue in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via bypassing the file extension fil... | 6.5 - MEDIUM | 2021-09-27 | 2021-10-08 |
| CVE-2020-13978 json | ** DISPUTED ** Monstra CMS 3.0.4 allows an attacker, who already has administrative access to modify .chunk.php files on the ... | 7.2 - HIGH | 2020-06-09 | 2023-11-07 |
| CVE-2020-13384 json | Monstra CMS 3.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via admin/index.php?id=filesmana... | 8.8 - HIGH | 2020-05-22 | 2020-05-26 |
| CVE-2020-8439 json | Monstra CMS through 3.0.4 allows remote authenticated users to take over arbitrary user accounts via a modified login paramet... | 6.5 - MEDIUM | 2020-03-07 | 2021-07-21 |
| CVE-2018-19599 json | Monstra CMS 1.6 allows XSS via an uploaded SVG document to the admin/index.php?id=filesmanager&path=uploads/ URI. NOTE: this ... | 5.4 - MEDIUM | 2020-03-02 | 2020-06-24 |
| CVE-2018-18694 json | admin/index.php?id=filesmanager in Monstra CMS 3.0.4 allows remote authenticated administrators to trigger stored XSS via Jav... | 4.8 - MEDIUM | 2018-10-29 | 2018-12-06 |
| CVE-2018-17418 json | Monstra CMS 3.0.4 allows remote attackers to execute arbitrary PHP code via a mixed-case file extension, as demonstrated by t... | 7.2 - HIGH | 2019-03-07 | 2019-03-08 |
| CVE-2018-17026 json | admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an edit_page&name=error404 action, a dif... | 4.8 - MEDIUM | 2018-09-13 | 2018-10-30 |
| CVE-2018-17025 json | admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an edit_page action for a page with no s... | 6.1 - MEDIUM | 2018-09-13 | 2018-10-30 |
| CVE-2018-17024 json | admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an add_page action. | 4.8 - MEDIUM | 2018-09-13 | 2019-07-23 |
| CVE-2018-16979 json | Monstra CMS V3.0.4 allows HTTP header injection in the plugins/captcha/crypt/cryptographp.php cfg parameter, a related issue ... | 6.1 - MEDIUM | 2018-09-12 | 2018-10-31 |
| CVE-2018-16978 json | Monstra CMS V3.0.4 has XSS when ones tries to register an account with a crafted password parameter to users/registration, a ... | 6.1 - MEDIUM | 2018-09-12 | 2018-10-31 |
| CVE-2018-16977 json | Monstra CMS V3.0.4 has an information leakage risk (e.g., PATH, DOCUMENT_ROOT, and SERVER_ADMIN) in libraries/Gelato/ErrorHan... | 5.3 - MEDIUM | 2018-09-12 | 2018-10-31 |
| CVE-2018-16820 json | admin/index.php in Monstra CMS 3.0.4 allows arbitrary directory listing via id=filesmanager&path=uploads/.......//./.......//... | 7.5 - HIGH | 2018-09-18 | 2018-11-07 |
Known software with vulnerabilities from Monstra
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Monstra | Monstra | 2.2.0 |
| Application | Monstra | Monstra Cms | 1.0.0 |