Записи monstra
43 опубликованных записей вендора monstra.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 2,3 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')18
- CWE-434 Unrestricted Upload of File with Dangerous Type9
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-384 Session Fixation2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
43 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
54В плане | CVE-2017-18048Готовый эксплойт | Monstra CMS 3.0.4 allows users to upload arbitrary files, which leads to remote command execution on the server, for example because .php (lmonstra · monstra · CWE-434 | Высокая8,8 | — | 63,4 % | 23 янв. 2018 г. |
40В плане | CVE-2021-36548Эксплойта нет | A remote code execution (RCE) vulnerability in the component /admin/index.php?id=themes&action=edit_template&filename=blog of Monstra v3.0.4monstra · monstra · CWE-434 | Критическая9,8 | — | 3,3 % | 28 окт. 2021 г. |
40В плане | CVE-2020-25414Эксплойта нет | A local file inclusion vulnerability was discovered in the captcha function in Monstra 3.0.4 which allows remote attackers to execute arbitrmonstra · monstra · CWE-829 | Критическая9,8 | — | 2,0 % | 17 июн. 2021 г. |
40В плане | CVE-2018-11678Эксплойта нет | plugins/box/users/users.plugin.php in Monstra CMS 3.0.4 allows Login Rate Limiting Bypass via manipulation of the login_attempts cookie.monstra · monstra cms · CWE-20 | Критическая9,8 | — | 1,7 % | 5 июн. 2018 г. |
39Наблюдать | CVE-2018-6383Proof of concept | Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .phamonstra · monstra · CWE-184 | Высокая8,8 | — | 13,5 % | 29 янв. 2018 г. |
39Наблюдать | CVE-2021-40940Эксплойта нет | Monstra 3.0.4 does not filter the case of php, which leads to an unrestricted file upload vulnerability.monstra · monstra · CWE-434 | Критическая9,8 | — | 1,6 % | 15 июн. 2022 г. |
36Наблюдать | CVE-2018-9037Эксплойта нет | Monstra CMS 3.0.4 allows remote code execution via an upload_file request for a .zip file, which is automatically extracted and may contain monstra · monstra · CWE-434 | Высокая8,8 | — | 2,8 % | 10 апр. 2018 г. |
36Наблюдать | CVE-2020-13384Эксплойта нет | Monstra CMS 3.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via admin/index.php?id=filesmanager because, fomonstra · monstra · CWE-434 | Высокая8,8 | — | 2,5 % | 22 мая 2020 г. |
35Наблюдать | CVE-2020-23219Эксплойта нет | Monstra CMS 3.0.4 allows attackers to execute arbitrary code via a crafted payload entered into the "Snippet content" field under the "Edit monstra · monstra cms · CWE-94 | Высокая8,8 | — | 1,6 % | 1 июл. 2021 г. |
35Наблюдать | CVE-2018-16608Эксплойта нет | In Monstra CMS 3.0.4, an attacker with 'Editor' privileges can change the password of the administrator via an admin/index.php?id=users&actimonstra · monstra · CWE-639 | Высокая8,8 | — | 1,2 % | 10 сент. 2018 г. |
35Наблюдать | CVE-2025-69906Proof of concept | Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin.monstra · monstra cms · CWE-434 | Высокая8,8 | — | 0,7 % | 5 февр. 2026 г. |
32Наблюдать | CVE-2018-11474Эксплойта нет | Monstra CMS 3.0.4 has a Session Management Issue in the Administrations Tab.monstra · monstra · CWE-384 | Высокая8,0 | — | 1,1 % | 25 мая 2018 г. |
32Наблюдать | CVE-2018-11475Эксплойта нет | Monstra CMS 3.0.4 has a Session Management Issue in the Users tab.monstra · monstra · CWE-384 | Высокая8,0 | — | 1,1 % | 25 мая 2018 г. |
31Наблюдать | CVE-2018-16820Эксплойта нет | admin/index.php in Monstra CMS 3.0.4 allows arbitrary directory listing via id=filesmanager&path=uploads/.......//./.......//./ requests.monstra · monstra · CWE-22 | Высокая7,5 | — | 2,0 % | 18 сент. 2018 г. |
29Наблюдать | CVE-2018-9038Proof of concept | Monstra CMS 3.0.4 allows remote attackers to delete files via an admin/index.php?id=filesmanager&delete_dir=./&path=uploads/ request.monstra · monstra · CWE-22 | Средняя6,5 | — | 9,3 % | 10 апр. 2018 г. |
29Наблюдать | CVE-2018-17418Proof of concept | Monstra CMS 3.0.4 allows remote attackers to execute arbitrary PHP code via a mixed-case file extension, as demonstrated by the 123.PhP filemonstra · monstra · CWE-434 | Высокая7,2 | — | 3,1 % | 7 мар. 2019 г. |
28Наблюдать | CVE-2018-15886Эксплойта нет | Monstra CMS 3.0.4 does not properly restrict modified Snippet content, as demonstrated by the admin/index.php?id=snippets&action=edit_snippemonstra · monstra · CWE-94 | Высокая7,2 | — | 1,6 % | 10 сент. 2018 г. |
28Наблюдать | CVE-2020-13978Эксплойта нет | Monstra CMS 3.0.4 allows an attacker, who already has administrative access to modify .chunk.php files on the Edit Chunk screen, to execute monstra · monstra cms · CWE-78 | Высокая7,2 | — | 1,3 % | 9 июн. 2020 г. |
28Наблюдать | CVE-2024-36774Эксплойта нет | An arbitrary file upload vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.monstra · monstra · CWE-434 | Высокая7,2 | — | 0,7 % | 6 июн. 2024 г. |
26Наблюдать | CVE-2020-8439Эксплойта нет | Monstra CMS through 3.0.4 allows remote authenticated users to take over arbitrary user accounts via a modified login parameter to an edit Umonstra · monstra · CWE-425 | Средняя6,5 | — | 1,6 % | 6 мар. 2020 г. |
26Наблюдать | CVE-2020-20691Эксплойта нет | An issue in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via bypassing the file extension filter and uploadimonstra · monstra cms · CWE-434 | Средняя6,5 | — | 0,9 % | 27 сент. 2021 г. |
25Наблюдать | CVE-2018-11227Proof of concept | Monstra CMS 3.0.4 and earlier has XSS via index.php.monstra · monstra cms · CWE-79 | Средняя6,1 | — | 4,7 % | 3 июл. 2019 г. |
25Наблюдать | CVE-2018-16979Proof of concept | Monstra CMS V3.0.4 allows HTTP header injection in the plugins/captcha/crypt/cryptographp.php cfg parameter, a related issue to CVE-2012-294monstra · monstra · CWE-113 | Средняя6,1 | — | 3,0 % | 12 сент. 2018 г. |
25Наблюдать | CVE-2018-11473Proof of concept | Monstra CMS 3.0.4 has XSS in the registration Form (i.e., the login parameter to users/registration).monstra · monstra · CWE-79 | Средняя6,1 | — | 2,3 % | 25 мая 2018 г. |
25Наблюдать | CVE-2018-14922Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in Monstra CMS 3.0.4 allow remote attackers to inject arbitrary web script or HTML via tmonstra · monstra · CWE-79 | Средняя6,1 | — | 2,0 % | 14 авг. 2018 г. |
- CVE-2017-1804854В плане
Monstra CMS 3.0.4 allows users to upload arbitrary files, which leads to remote command execution on the server, for example because .php (l
ВысокаяCVSS 8,8Готовый эксплойтEPSS 63 %monstra · monstra23 янв. 2018 г.
- CVE-2021-3654840В плане
A remote code execution (RCE) vulnerability in the component /admin/index.php?id=themes&action=edit_template&filename=blog of Monstra v3.0.4
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %monstra · monstra28 окт. 2021 г.
- CVE-2020-2541440В плане
A local file inclusion vulnerability was discovered in the captcha function in Monstra 3.0.4 which allows remote attackers to execute arbitr
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %monstra · monstra17 июн. 2021 г.
- CVE-2018-1167840В плане
plugins/box/users/users.plugin.php in Monstra CMS 3.0.4 allows Login Rate Limiting Bypass via manipulation of the login_attempts cookie.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %monstra · monstra cms5 июн. 2018 г.
- CVE-2018-638339Наблюдать
Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .pha
ВысокаяCVSS 8,8Proof of conceptEPSS 13 %monstra · monstra29 янв. 2018 г.
- CVE-2021-4094039Наблюдать
Monstra 3.0.4 does not filter the case of php, which leads to an unrestricted file upload vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %monstra · monstra15 июн. 2022 г.
- CVE-2018-903736Наблюдать
Monstra CMS 3.0.4 allows remote code execution via an upload_file request for a .zip file, which is automatically extracted and may contain
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %monstra · monstra10 апр. 2018 г.
- CVE-2020-1338436Наблюдать
Monstra CMS 3.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via admin/index.php?id=filesmanager because, fo
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %monstra · monstra22 мая 2020 г.
- CVE-2020-2321935Наблюдать
Monstra CMS 3.0.4 allows attackers to execute arbitrary code via a crafted payload entered into the "Snippet content" field under the "Edit
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %monstra · monstra cms1 июл. 2021 г.
- CVE-2018-1660835Наблюдать
In Monstra CMS 3.0.4, an attacker with 'Editor' privileges can change the password of the administrator via an admin/index.php?id=users&acti
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %monstra · monstra10 сент. 2018 г.
- CVE-2025-6990635Наблюдать
Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin.
ВысокаяCVSS 8,8Proof of conceptEPSS 1 %monstra · monstra cms5 февр. 2026 г.
- CVE-2018-1147432Наблюдать
Monstra CMS 3.0.4 has a Session Management Issue in the Administrations Tab.
ВысокаяCVSS 8,0Эксплойта нетEPSS 1 %monstra · monstra25 мая 2018 г.
- CVE-2018-1147532Наблюдать
Monstra CMS 3.0.4 has a Session Management Issue in the Users tab.
ВысокаяCVSS 8,0Эксплойта нетEPSS 1 %monstra · monstra25 мая 2018 г.
- CVE-2018-1682031Наблюдать
admin/index.php in Monstra CMS 3.0.4 allows arbitrary directory listing via id=filesmanager&path=uploads/.......//./.......//./ requests.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %monstra · monstra18 сент. 2018 г.
- CVE-2018-903829Наблюдать
Monstra CMS 3.0.4 allows remote attackers to delete files via an admin/index.php?id=filesmanager&delete_dir=./&path=uploads/ request.
СредняяCVSS 6,5Proof of conceptEPSS 9 %monstra · monstra10 апр. 2018 г.
- CVE-2018-1741829Наблюдать
Monstra CMS 3.0.4 allows remote attackers to execute arbitrary PHP code via a mixed-case file extension, as demonstrated by the 123.PhP file
ВысокаяCVSS 7,2Proof of conceptEPSS 3 %monstra · monstra7 мар. 2019 г.
- CVE-2018-1588628Наблюдать
Monstra CMS 3.0.4 does not properly restrict modified Snippet content, as demonstrated by the admin/index.php?id=snippets&action=edit_snippe
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %monstra · monstra10 сент. 2018 г.
- CVE-2020-1397828Наблюдать
Monstra CMS 3.0.4 allows an attacker, who already has administrative access to modify .chunk.php files on the Edit Chunk screen, to execute
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %monstra · monstra cms9 июн. 2020 г.
- CVE-2024-3677428Наблюдать
An arbitrary file upload vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %monstra · monstra6 июн. 2024 г.
- CVE-2020-843926Наблюдать
Monstra CMS through 3.0.4 allows remote authenticated users to take over arbitrary user accounts via a modified login parameter to an edit U
СредняяCVSS 6,5Эксплойта нетEPSS 2 %monstra · monstra6 мар. 2020 г.
- CVE-2020-2069126Наблюдать
An issue in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via bypassing the file extension filter and uploadi
СредняяCVSS 6,5Эксплойта нетEPSS 1 %monstra · monstra cms27 сент. 2021 г.
- CVE-2018-1122725Наблюдать
Monstra CMS 3.0.4 and earlier has XSS via index.php.
СредняяCVSS 6,1Proof of conceptEPSS 5 %monstra · monstra cms3 июл. 2019 г.
- CVE-2018-1697925Наблюдать
Monstra CMS V3.0.4 allows HTTP header injection in the plugins/captcha/crypt/cryptographp.php cfg parameter, a related issue to CVE-2012-294
СредняяCVSS 6,1Proof of conceptEPSS 3 %monstra · monstra12 сент. 2018 г.
- CVE-2018-1147325Наблюдать
Monstra CMS 3.0.4 has XSS in the registration Form (i.e., the login parameter to users/registration).
СредняяCVSS 6,1Proof of conceptEPSS 2 %monstra · monstra25 мая 2018 г.
- CVE-2018-1492225Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in Monstra CMS 3.0.4 allow remote attackers to inject arbitrary web script or HTML via t
СредняяCVSS 6,1Эксплойта нетEPSS 2 %monstra · monstra14 авг. 2018 г.