Vulnerability index

Browse CVEs

35 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Monstra Cms HIGH 8.8
CVE-2025-69906

Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin. The application relies on blacklist-based file extens…

No fix yet
Fix from $1,950 2026-02-05
Monstra HIGH 7.2
CVE-2024-36774

An arbitrary file upload vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.

No fix yet
Fix from $1,950 2024-06-06
Monstra MEDIUM 5.4
CVE-2024-36775

A cross-site scripting (XSS) vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inje…

No fix yet
Fix from $1,600 2024-06-06
Monstra CRITICAL 9.8
CVE-2021-40940

Monstra 3.0.4 does not filter the case of php, which leads to an unrestricted file upload vulnerability.

Fix: after 3.0.4
Fix from $2,300 2022-06-15
Monstra CRITICAL 9.8
CVE-2021-36548

A remote code execution (RCE) vulnerability in the component /admin/index.php?id=themes&action=edit_template&filename=blog of Monstra v3.0.4 allows a…

No fix yet
Fix from $2,300 2021-10-28
Monstra Cms MEDIUM 6.5
CVE-2020-20691

An issue in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via bypassing the file extension filter and uploading crafte…

No fix yet
Fix from $1,600 2021-09-27
Monstra Cms MEDIUM 5.4
CVE-2020-23697

Cross Site Scripting vulnerabilty in Monstra CMS 3.0.4 via the page feature in admin/index.php.

No fix yet
Fix from $1,600 2021-07-06
Monstra Cms HIGH 8.8
CVE-2020-23219

Monstra CMS 3.0.4 allows attackers to execute arbitrary code via a crafted payload entered into the "Snippet content" field under the "Edit Snippet" …

No fix yet
Fix from $1,950 2021-07-01
Monstra Cms MEDIUM 5.4
CVE-2020-23205

A stored cross site scripting (XSS) vulnerability in Monstra CMS version 3.0.4 allows attackers to execute arbitrary web scripts or HTML via crafted …

No fix yet
Fix from $1,600 2021-07-01
Monstra CRITICAL 9.8
CVE-2020-25414

A local file inclusion vulnerability was discovered in the captcha function in Monstra 3.0.4 which allows remote attackers to execute arbitrary PHP c…

No fix yet
Fix from $2,300 2021-06-17
Monstra Cms HIGH 7.2
CVE-2020-13978

Monstra CMS 3.0.4 allows an attacker, who already has administrative access to modify .chunk.php files on the Edit Chunk screen, to execute arbitrary…

No fix yet
Fix from $1,950 2020-06-09
Monstra HIGH 8.8
CVE-2020-13384

Monstra CMS 3.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via admin/index.php?id=filesmanager because, for example…

No fix yet
Fix from $1,950 2020-05-22
Monstra MEDIUM 6.5
CVE-2020-8439

Monstra CMS through 3.0.4 allows remote authenticated users to take over arbitrary user accounts via a modified login parameter to an edit URI, as de…

Fix: after 3.0.4
Fix from $1,600 2020-03-07
Monstra Cms MEDIUM 5.4
CVE-2018-19599

Monstra CMS 1.6 allows XSS via an uploaded SVG document to the admin/index.php?id=filesmanager&path=uploads/ URI. NOTE: this is a discontinued produc…

No fix yet
Fix from $1,600 2020-03-02
Monstra Cms MEDIUM 6.1
CVE-2018-11227

Monstra CMS 3.0.4 and earlier has XSS via index.php.

Fix: 3.0.4+
Fix from $1,600 2019-07-03
Monstra HIGH 7.2
CVE-2018-17418

Monstra CMS 3.0.4 allows remote attackers to execute arbitrary PHP code via a mixed-case file extension, as demonstrated by the 123.PhP filename, bec…

No fix yet
Fix from $1,950 2019-03-07
Monstra HIGH 7.5
CVE-2018-16820

admin/index.php in Monstra CMS 3.0.4 allows arbitrary directory listing via id=filesmanager&path=uploads/.......//./.......//./ requests.

No fix yet
Fix from $1,950 2018-09-18
Monstra MEDIUM 6.1
CVE-2018-17025

admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an edit_page action for a page with no special role.

No fix yet
Fix from $1,600 2018-09-13
Monstra MEDIUM 6.1
CVE-2018-16978

Monstra CMS V3.0.4 has XSS when ones tries to register an account with a crafted password parameter to users/registration, a different vulnerability …

No fix yet
Fix from $1,600 2018-09-12
Monstra MEDIUM 6.1
CVE-2018-16979

Monstra CMS V3.0.4 allows HTTP header injection in the plugins/captcha/crypt/cryptographp.php cfg parameter, a related issue to CVE-2012-2943.

No fix yet
Fix from $1,600 2018-09-12
Monstra MEDIUM 5.3
CVE-2018-16977

Monstra CMS V3.0.4 has an information leakage risk (e.g., PATH, DOCUMENT_ROOT, and SERVER_ADMIN) in libraries/Gelato/ErrorHandler/Resources/Views/Err…

No fix yet
Fix from $1,600 2018-09-12
Monstra HIGH 8.8
CVE-2018-16608

In Monstra CMS 3.0.4, an attacker with 'Editor' privileges can change the password of the administrator via an admin/index.php?id=users&action=edit&u…

No fix yet
Fix from $1,950 2018-09-10
Monstra HIGH 7.2
CVE-2018-15886

Monstra CMS 3.0.4 does not properly restrict modified Snippet content, as demonstrated by the admin/index.php?id=snippets&action=edit_snippet&filenam…

No fix yet
Fix from $1,950 2018-09-10
Monstra MEDIUM 6.1
CVE-2018-14922

Multiple cross-site scripting (XSS) vulnerabilities in Monstra CMS 3.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) fi…

No fix yet
Fix from $1,600 2018-08-14
Monstra Cms CRITICAL 9.8
CVE-2018-11678

plugins/box/users/users.plugin.php in Monstra CMS 3.0.4 allows Login Rate Limiting Bypass via manipulation of the login_attempts cookie.

No fix yet
Fix from $2,300 2018-06-05
Monstra HIGH 8.0
CVE-2018-11474

Monstra CMS 3.0.4 has a Session Management Issue in the Administrations Tab. A password change at admin/index.php?id=users&action=edit&user_id=1 does…

Mitigation only
Fix from $1,950 2018-05-25
Monstra HIGH 8.0
CVE-2018-11475

Monstra CMS 3.0.4 has a Session Management Issue in the Users tab. A password change at users/1/edit does not invalidate a session that is open in a …

Mitigation only
Fix from $1,950 2018-05-25
Monstra MEDIUM 6.1
CVE-2018-11472

Monstra CMS 3.0.4 has Reflected XSS during Login (i.e., the login parameter to admin/index.php).

Mitigation only
Fix from $1,600 2018-05-25
Monstra MEDIUM 6.1
CVE-2018-11473

Monstra CMS 3.0.4 has XSS in the registration Form (i.e., the login parameter to users/registration).

Mitigation only
Fix from $1,600 2018-05-25
Monstra HIGH 8.8
CVE-2018-9037

Monstra CMS 3.0.4 allows remote code execution via an upload_file request for a .zip file, which is automatically extracted and may contain .php file…

No fix yet
Fix from $1,950 2018-04-10