İçeriğe atla
Noroxi

monstra kayıtları

monstra üreticisine ait 43 yayımlanmış kayıt.

Tüm kayıtlar

43 kayıt
  • CVE-2017-18048
    54Planlayın

    Monstra CMS 3.0.4 allows users to upload arbitrary files, which leads to remote command execution on the server, for example because .php (l

    YüksekCVSS 8,8SilahlaştırılmışEPSS %63

    monstra · monstra23 Oca 2018

  • CVE-2021-36548
    40Planlayın

    A remote code execution (RCE) vulnerability in the component /admin/index.php?id=themes&action=edit_template&filename=blog of Monstra v3.0.4

    KritikCVSS 9,8İstismar yokEPSS %3

    monstra · monstra28 Eki 2021

  • CVE-2020-25414
    40Planlayın

    A local file inclusion vulnerability was discovered in the captcha function in Monstra 3.0.4 which allows remote attackers to execute arbitr

    KritikCVSS 9,8İstismar yokEPSS %2

    monstra · monstra17 Haz 2021

  • CVE-2018-11678
    40Planlayın

    plugins/box/users/users.plugin.php in Monstra CMS 3.0.4 allows Login Rate Limiting Bypass via manipulation of the login_attempts cookie.

    KritikCVSS 9,8İstismar yokEPSS %2

    monstra · monstra cms5 Haz 2018

  • CVE-2018-6383
    39İzleyin

    Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .pha

    YüksekCVSS 8,8Kavram kanıtıEPSS %13

    monstra · monstra29 Oca 2018

  • CVE-2021-40940
    39İzleyin

    Monstra 3.0.4 does not filter the case of php, which leads to an unrestricted file upload vulnerability.

    KritikCVSS 9,8İstismar yokEPSS %2

    monstra · monstra15 Haz 2022

  • CVE-2018-9037
    36İzleyin

    Monstra CMS 3.0.4 allows remote code execution via an upload_file request for a .zip file, which is automatically extracted and may contain

    YüksekCVSS 8,8İstismar yokEPSS %3

    monstra · monstra10 Nis 2018

  • CVE-2020-13384
    36İzleyin

    Monstra CMS 3.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via admin/index.php?id=filesmanager because, fo

    YüksekCVSS 8,8İstismar yokEPSS %3

    monstra · monstra22 May 2020

  • CVE-2020-23219
    35İzleyin

    Monstra CMS 3.0.4 allows attackers to execute arbitrary code via a crafted payload entered into the "Snippet content" field under the "Edit

    YüksekCVSS 8,8İstismar yokEPSS %2

    monstra · monstra cms1 Tem 2021

  • CVE-2018-16608
    35İzleyin

    In Monstra CMS 3.0.4, an attacker with 'Editor' privileges can change the password of the administrator via an admin/index.php?id=users&acti

    YüksekCVSS 8,8İstismar yokEPSS %1

    monstra · monstra10 Eyl 2018

  • CVE-2025-69906
    35İzleyin

    Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin.

    YüksekCVSS 8,8Kavram kanıtıEPSS %1

    monstra · monstra cms5 Şub 2026

  • CVE-2018-11474
    32İzleyin

    Monstra CMS 3.0.4 has a Session Management Issue in the Administrations Tab.

    YüksekCVSS 8,0İstismar yokEPSS %1

    monstra · monstra25 May 2018

  • CVE-2018-11475
    32İzleyin

    Monstra CMS 3.0.4 has a Session Management Issue in the Users tab.

    YüksekCVSS 8,0İstismar yokEPSS %1

    monstra · monstra25 May 2018

  • CVE-2018-16820
    31İzleyin

    admin/index.php in Monstra CMS 3.0.4 allows arbitrary directory listing via id=filesmanager&path=uploads/.......//./.......//./ requests.

    YüksekCVSS 7,5İstismar yokEPSS %2

    monstra · monstra18 Eyl 2018

  • CVE-2018-9038
    29İzleyin

    Monstra CMS 3.0.4 allows remote attackers to delete files via an admin/index.php?id=filesmanager&delete_dir=./&path=uploads/ request.

    OrtaCVSS 6,5Kavram kanıtıEPSS %9

    monstra · monstra10 Nis 2018

  • CVE-2018-17418
    29İzleyin

    Monstra CMS 3.0.4 allows remote attackers to execute arbitrary PHP code via a mixed-case file extension, as demonstrated by the 123.PhP file

    YüksekCVSS 7,2Kavram kanıtıEPSS %3

    monstra · monstra7 Mar 2019

  • CVE-2018-15886
    28İzleyin

    Monstra CMS 3.0.4 does not properly restrict modified Snippet content, as demonstrated by the admin/index.php?id=snippets&action=edit_snippe

    YüksekCVSS 7,2İstismar yokEPSS %2

    monstra · monstra10 Eyl 2018

  • CVE-2020-13978
    28İzleyin

    Monstra CMS 3.0.4 allows an attacker, who already has administrative access to modify .chunk.php files on the Edit Chunk screen, to execute

    YüksekCVSS 7,2İstismar yokEPSS %1

    monstra · monstra cms9 Haz 2020

  • CVE-2024-36774
    28İzleyin

    An arbitrary file upload vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.

    YüksekCVSS 7,2İstismar yokEPSS %1

    monstra · monstra6 Haz 2024

  • CVE-2020-8439
    26İzleyin

    Monstra CMS through 3.0.4 allows remote authenticated users to take over arbitrary user accounts via a modified login parameter to an edit U

    OrtaCVSS 6,5İstismar yokEPSS %2

    monstra · monstra6 Mar 2020

  • CVE-2020-20691
    26İzleyin

    An issue in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via bypassing the file extension filter and uploadi

    OrtaCVSS 6,5İstismar yokEPSS %1

    monstra · monstra cms27 Eyl 2021

  • CVE-2018-11227
    25İzleyin

    Monstra CMS 3.0.4 and earlier has XSS via index.php.

    OrtaCVSS 6,1Kavram kanıtıEPSS %5

    monstra · monstra cms3 Tem 2019

  • CVE-2018-16979
    25İzleyin

    Monstra CMS V3.0.4 allows HTTP header injection in the plugins/captcha/crypt/cryptographp.php cfg parameter, a related issue to CVE-2012-294

    OrtaCVSS 6,1Kavram kanıtıEPSS %3

    monstra · monstra12 Eyl 2018

  • CVE-2018-11473
    25İzleyin

    Monstra CMS 3.0.4 has XSS in the registration Form (i.e., the login parameter to users/registration).

    OrtaCVSS 6,1Kavram kanıtıEPSS %2

    monstra · monstra25 May 2018

  • CVE-2018-14922
    25İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in Monstra CMS 3.0.4 allow remote attackers to inject arbitrary web script or HTML via t

    OrtaCVSS 6,1İstismar yokEPSS %2

    monstra · monstra14 Ağu 2018