Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
Monstra
MEDIUM 6.5
CVE-2018-9038EPSS 9%
Monstra CMS 3.0.4 allows remote attackers to delete files via an admin/index.php?id=filesmanager&delete_dir=./&path=uploads/ request.
No fix yet
Fix from $1,600
2018-04-10
Monstra
MEDIUM 5.4
CVE-2018-6550
Monstra CMS through 3.0.4 has XSS in the title function in plugins/box/pages/pages.plugin.php via a page title to admin/index.php.
Fix: after 3.0.4
Fix from $1,600
2018-02-02
Monstra
HIGH 8.8
CVE-2018-6383EPSS 13%
Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .phar extensi…
Fix: after 3.0.4
Fix from $1,950
2018-01-29
Monstra
HIGH 8.8
CVE-2017-18048EPSS 63%
Monstra CMS 3.0.4 allows users to upload arbitrary files, which leads to remote command execution on the server, for example because .php (lowercase)…
Patch available
Fix from $1,950
2018-01-23
Monstra
MEDIUM 5.0
CVE-2014-9006
Monstra 3.0.1 and earlier uses a cookie to track how many login attempts have been attempted, which allows remote attackers to conduct brute force lo…
Fix: after 3.0.1
Fix from $1,600
2014-11-20