Products: 2
    Vulnerabilities: 43
    Known Exploited: 0
    4
    Critical Level Threats
    14
    High Level Threats
    25
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-69906

    Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin. The application relies on blacklist-based file extension validation and stores uploaded files directly in a web-accessible directory. Under typical server configurations, this can allow an attacker to upload files that are interpreted as executable code, resulting in remote code execution.

    Last Modified: Feb 11, 2026
    Published: Feb 05, 2026

    CVE-2024-36773

    A cross-site scripting (XSS) vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Themes parameter at index.php.

    Last Modified: Feb 13, 2025
    Published: Jun 07, 2024

    CVE-2024-36775

    A cross-site scripting (XSS) vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the About Me parameter in the Edit Profile page.

    Last Modified: Feb 13, 2025
    Published: Jun 06, 2024

    CVE-2024-36774

    An arbitrary file upload vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.

    Last Modified: Feb 13, 2025
    Published: Jun 06, 2024

    CVE-2021-40940

    Monstra 3.0.4 does not filter the case of php, which leads to an unrestricted file upload vulnerability.

    Last Modified: Nov 21, 2024
    Published: Jun 15, 2022
    Items Per Page
    Monstra Vulnerabilities & Security CVEs | CVE-DB