Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Monsta Ftp CRITICAL 9.8
CVE-2025-34299EPSS 73%

Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers to execu…

Fix: after 2.11
Fix from $2,300 2025-11-07
Monstaftp CRITICAL 9.1
CVE-2022-31827EPSS 21%

MonstaFTP v2.10.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the function performFetchRequest at HTTPFetcher.php.

No fix yet
Fix from $2,300 2022-06-09
Monsta Ftp CRITICAL 9.8
CVE-2022-27468

Monstaftp v2.10.3 was discovered to contain an arbitrary file upload which allows attackers to execute arbitrary code via a crafted file uploaded to …

No fix yet
Fix from $2,300 2022-04-26
Monsta Ftp CRITICAL 9.8
CVE-2022-27469

Monstaftp v2.10.3 was discovered to allow attackers to execute Server-Side Request Forgery (SSRF).

No fix yet
Fix from $2,300 2022-04-26
Monsta Ftp CRITICAL 9.8
CVE-2020-14057

Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations. This allows attackers to read and write arbitrary local fi…

Fix: after 2.10.1
Fix from $2,300 2020-07-01
Monsta Ftp CRITICAL 9.8
CVE-2020-14056

Monsta FTP 2.10.1 or below is prone to a server-side request forgery vulnerability due to insufficient restriction of the web fetch functionality. Th…

Fix: after 2.10.1
Fix from $2,300 2020-07-01
Monsta Ftp MEDIUM 6.1
CVE-2020-14055

Monsta FTP 2.10.1 or below is prone to a stored cross-site scripting vulnerability in the language setting due to insufficient output encoding.

Fix: after 2.10.1
Fix from $1,600 2020-07-01