Перейти к содержимому
Noroxi

Записи monstra

43 опубликованных записей вендора monstra.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
1 · 2,3 %
Pre-auth RCE
3
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

43 записей
  • CVE-2017-18048
    54В плане

    Monstra CMS 3.0.4 allows users to upload arbitrary files, which leads to remote command execution on the server, for example because .php (l

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 63 %

    monstra · monstra23 янв. 2018 г.

  • CVE-2021-36548
    40В плане

    A remote code execution (RCE) vulnerability in the component /admin/index.php?id=themes&action=edit_template&filename=blog of Monstra v3.0.4

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    monstra · monstra28 окт. 2021 г.

  • CVE-2020-25414
    40В плане

    A local file inclusion vulnerability was discovered in the captcha function in Monstra 3.0.4 which allows remote attackers to execute arbitr

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    monstra · monstra17 июн. 2021 г.

  • CVE-2018-11678
    40В плане

    plugins/box/users/users.plugin.php in Monstra CMS 3.0.4 allows Login Rate Limiting Bypass via manipulation of the login_attempts cookie.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    monstra · monstra cms5 июн. 2018 г.

  • CVE-2018-6383
    39Наблюдать

    Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .pha

    ВысокаяCVSS 8,8Proof of conceptEPSS 13 %

    monstra · monstra29 янв. 2018 г.

  • CVE-2021-40940
    39Наблюдать

    Monstra 3.0.4 does not filter the case of php, which leads to an unrestricted file upload vulnerability.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    monstra · monstra15 июн. 2022 г.

  • CVE-2018-9037
    36Наблюдать

    Monstra CMS 3.0.4 allows remote code execution via an upload_file request for a .zip file, which is automatically extracted and may contain

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    monstra · monstra10 апр. 2018 г.

  • CVE-2020-13384
    36Наблюдать

    Monstra CMS 3.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via admin/index.php?id=filesmanager because, fo

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    monstra · monstra22 мая 2020 г.

  • CVE-2020-23219
    35Наблюдать

    Monstra CMS 3.0.4 allows attackers to execute arbitrary code via a crafted payload entered into the "Snippet content" field under the "Edit

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    monstra · monstra cms1 июл. 2021 г.

  • CVE-2018-16608
    35Наблюдать

    In Monstra CMS 3.0.4, an attacker with 'Editor' privileges can change the password of the administrator via an admin/index.php?id=users&acti

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    monstra · monstra10 сент. 2018 г.

  • CVE-2025-69906
    35Наблюдать

    Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin.

    ВысокаяCVSS 8,8Proof of conceptEPSS 1 %

    monstra · monstra cms5 февр. 2026 г.

  • CVE-2018-11474
    32Наблюдать

    Monstra CMS 3.0.4 has a Session Management Issue in the Administrations Tab.

    ВысокаяCVSS 8,0Эксплойта нетEPSS 1 %

    monstra · monstra25 мая 2018 г.

  • CVE-2018-11475
    32Наблюдать

    Monstra CMS 3.0.4 has a Session Management Issue in the Users tab.

    ВысокаяCVSS 8,0Эксплойта нетEPSS 1 %

    monstra · monstra25 мая 2018 г.

  • CVE-2018-16820
    31Наблюдать

    admin/index.php in Monstra CMS 3.0.4 allows arbitrary directory listing via id=filesmanager&path=uploads/.......//./.......//./ requests.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    monstra · monstra18 сент. 2018 г.

  • CVE-2018-9038
    29Наблюдать

    Monstra CMS 3.0.4 allows remote attackers to delete files via an admin/index.php?id=filesmanager&delete_dir=./&path=uploads/ request.

    СредняяCVSS 6,5Proof of conceptEPSS 9 %

    monstra · monstra10 апр. 2018 г.

  • CVE-2018-17418
    29Наблюдать

    Monstra CMS 3.0.4 allows remote attackers to execute arbitrary PHP code via a mixed-case file extension, as demonstrated by the 123.PhP file

    ВысокаяCVSS 7,2Proof of conceptEPSS 3 %

    monstra · monstra7 мар. 2019 г.

  • CVE-2018-15886
    28Наблюдать

    Monstra CMS 3.0.4 does not properly restrict modified Snippet content, as demonstrated by the admin/index.php?id=snippets&action=edit_snippe

    ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %

    monstra · monstra10 сент. 2018 г.

  • CVE-2020-13978
    28Наблюдать

    Monstra CMS 3.0.4 allows an attacker, who already has administrative access to modify .chunk.php files on the Edit Chunk screen, to execute

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    monstra · monstra cms9 июн. 2020 г.

  • CVE-2024-36774
    28Наблюдать

    An arbitrary file upload vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    monstra · monstra6 июн. 2024 г.

  • CVE-2020-8439
    26Наблюдать

    Monstra CMS through 3.0.4 allows remote authenticated users to take over arbitrary user accounts via a modified login parameter to an edit U

    СредняяCVSS 6,5Эксплойта нетEPSS 2 %

    monstra · monstra6 мар. 2020 г.

  • CVE-2020-20691
    26Наблюдать

    An issue in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via bypassing the file extension filter and uploadi

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    monstra · monstra cms27 сент. 2021 г.

  • CVE-2018-11227
    25Наблюдать

    Monstra CMS 3.0.4 and earlier has XSS via index.php.

    СредняяCVSS 6,1Proof of conceptEPSS 5 %

    monstra · monstra cms3 июл. 2019 г.

  • CVE-2018-16979
    25Наблюдать

    Monstra CMS V3.0.4 allows HTTP header injection in the plugins/captcha/crypt/cryptographp.php cfg parameter, a related issue to CVE-2012-294

    СредняяCVSS 6,1Proof of conceptEPSS 3 %

    monstra · monstra12 сент. 2018 г.

  • CVE-2018-11473
    25Наблюдать

    Monstra CMS 3.0.4 has XSS in the registration Form (i.e., the login parameter to users/registration).

    СредняяCVSS 6,1Proof of conceptEPSS 2 %

    monstra · monstra25 мая 2018 г.

  • CVE-2018-14922
    25Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in Monstra CMS 3.0.4 allow remote attackers to inject arbitrary web script or HTML via t

    СредняяCVSS 6,1Эксплойта нетEPSS 2 %

    monstra · monstra14 авг. 2018 г.