monstra kayıtları
monstra üreticisine ait 43 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %2,3
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')18
- CWE-434 Unrestricted Upload of File with Dangerous Type9
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-384 Session Fixation2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
43 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
54Planlayın | CVE-2017-18048Silahlaştırılmış | Monstra CMS 3.0.4 allows users to upload arbitrary files, which leads to remote command execution on the server, for example because .php (lmonstra · monstra · CWE-434 | Yüksek8,8 | — | %63,4 | 23 Oca 2018 |
40Planlayın | CVE-2021-36548İstismar yok | A remote code execution (RCE) vulnerability in the component /admin/index.php?id=themes&action=edit_template&filename=blog of Monstra v3.0.4monstra · monstra · CWE-434 | Kritik9,8 | — | %3,3 | 28 Eki 2021 |
40Planlayın | CVE-2020-25414İstismar yok | A local file inclusion vulnerability was discovered in the captcha function in Monstra 3.0.4 which allows remote attackers to execute arbitrmonstra · monstra · CWE-829 | Kritik9,8 | — | %2,0 | 17 Haz 2021 |
40Planlayın | CVE-2018-11678İstismar yok | plugins/box/users/users.plugin.php in Monstra CMS 3.0.4 allows Login Rate Limiting Bypass via manipulation of the login_attempts cookie.monstra · monstra cms · CWE-20 | Kritik9,8 | — | %1,7 | 5 Haz 2018 |
39İzleyin | CVE-2018-6383Kavram kanıtı | Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .phamonstra · monstra · CWE-184 | Yüksek8,8 | — | %13,5 | 29 Oca 2018 |
39İzleyin | CVE-2021-40940İstismar yok | Monstra 3.0.4 does not filter the case of php, which leads to an unrestricted file upload vulnerability.monstra · monstra · CWE-434 | Kritik9,8 | — | %1,6 | 15 Haz 2022 |
36İzleyin | CVE-2018-9037İstismar yok | Monstra CMS 3.0.4 allows remote code execution via an upload_file request for a .zip file, which is automatically extracted and may contain monstra · monstra · CWE-434 | Yüksek8,8 | — | %2,8 | 10 Nis 2018 |
36İzleyin | CVE-2020-13384İstismar yok | Monstra CMS 3.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via admin/index.php?id=filesmanager because, fomonstra · monstra · CWE-434 | Yüksek8,8 | — | %2,5 | 22 May 2020 |
35İzleyin | CVE-2020-23219İstismar yok | Monstra CMS 3.0.4 allows attackers to execute arbitrary code via a crafted payload entered into the "Snippet content" field under the "Edit monstra · monstra cms · CWE-94 | Yüksek8,8 | — | %1,6 | 1 Tem 2021 |
35İzleyin | CVE-2018-16608İstismar yok | In Monstra CMS 3.0.4, an attacker with 'Editor' privileges can change the password of the administrator via an admin/index.php?id=users&actimonstra · monstra · CWE-639 | Yüksek8,8 | — | %1,2 | 10 Eyl 2018 |
35İzleyin | CVE-2025-69906Kavram kanıtı | Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin.monstra · monstra cms · CWE-434 | Yüksek8,8 | — | %0,7 | 5 Şub 2026 |
32İzleyin | CVE-2018-11474İstismar yok | Monstra CMS 3.0.4 has a Session Management Issue in the Administrations Tab.monstra · monstra · CWE-384 | Yüksek8,0 | — | %1,1 | 25 May 2018 |
32İzleyin | CVE-2018-11475İstismar yok | Monstra CMS 3.0.4 has a Session Management Issue in the Users tab.monstra · monstra · CWE-384 | Yüksek8,0 | — | %1,1 | 25 May 2018 |
31İzleyin | CVE-2018-16820İstismar yok | admin/index.php in Monstra CMS 3.0.4 allows arbitrary directory listing via id=filesmanager&path=uploads/.......//./.......//./ requests.monstra · monstra · CWE-22 | Yüksek7,5 | — | %2,0 | 18 Eyl 2018 |
29İzleyin | CVE-2018-9038Kavram kanıtı | Monstra CMS 3.0.4 allows remote attackers to delete files via an admin/index.php?id=filesmanager&delete_dir=./&path=uploads/ request.monstra · monstra · CWE-22 | Orta6,5 | — | %9,3 | 10 Nis 2018 |
29İzleyin | CVE-2018-17418Kavram kanıtı | Monstra CMS 3.0.4 allows remote attackers to execute arbitrary PHP code via a mixed-case file extension, as demonstrated by the 123.PhP filemonstra · monstra · CWE-434 | Yüksek7,2 | — | %3,1 | 7 Mar 2019 |
28İzleyin | CVE-2018-15886İstismar yok | Monstra CMS 3.0.4 does not properly restrict modified Snippet content, as demonstrated by the admin/index.php?id=snippets&action=edit_snippemonstra · monstra · CWE-94 | Yüksek7,2 | — | %1,6 | 10 Eyl 2018 |
28İzleyin | CVE-2020-13978İstismar yok | Monstra CMS 3.0.4 allows an attacker, who already has administrative access to modify .chunk.php files on the Edit Chunk screen, to execute monstra · monstra cms · CWE-78 | Yüksek7,2 | — | %1,3 | 9 Haz 2020 |
28İzleyin | CVE-2024-36774İstismar yok | An arbitrary file upload vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.monstra · monstra · CWE-434 | Yüksek7,2 | — | %0,7 | 6 Haz 2024 |
26İzleyin | CVE-2020-8439İstismar yok | Monstra CMS through 3.0.4 allows remote authenticated users to take over arbitrary user accounts via a modified login parameter to an edit Umonstra · monstra · CWE-425 | Orta6,5 | — | %1,6 | 6 Mar 2020 |
26İzleyin | CVE-2020-20691İstismar yok | An issue in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via bypassing the file extension filter and uploadimonstra · monstra cms · CWE-434 | Orta6,5 | — | %0,9 | 27 Eyl 2021 |
25İzleyin | CVE-2018-11227Kavram kanıtı | Monstra CMS 3.0.4 and earlier has XSS via index.php.monstra · monstra cms · CWE-79 | Orta6,1 | — | %4,7 | 3 Tem 2019 |
25İzleyin | CVE-2018-16979Kavram kanıtı | Monstra CMS V3.0.4 allows HTTP header injection in the plugins/captcha/crypt/cryptographp.php cfg parameter, a related issue to CVE-2012-294monstra · monstra · CWE-113 | Orta6,1 | — | %3,0 | 12 Eyl 2018 |
25İzleyin | CVE-2018-11473Kavram kanıtı | Monstra CMS 3.0.4 has XSS in the registration Form (i.e., the login parameter to users/registration).monstra · monstra · CWE-79 | Orta6,1 | — | %2,3 | 25 May 2018 |
25İzleyin | CVE-2018-14922İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in Monstra CMS 3.0.4 allow remote attackers to inject arbitrary web script or HTML via tmonstra · monstra · CWE-79 | Orta6,1 | — | %2,0 | 14 Ağu 2018 |
- CVE-2017-1804854Planlayın
Monstra CMS 3.0.4 allows users to upload arbitrary files, which leads to remote command execution on the server, for example because .php (l
YüksekCVSS 8,8SilahlaştırılmışEPSS %63monstra · monstra23 Oca 2018
- CVE-2021-3654840Planlayın
A remote code execution (RCE) vulnerability in the component /admin/index.php?id=themes&action=edit_template&filename=blog of Monstra v3.0.4
KritikCVSS 9,8İstismar yokEPSS %3monstra · monstra28 Eki 2021
- CVE-2020-2541440Planlayın
A local file inclusion vulnerability was discovered in the captcha function in Monstra 3.0.4 which allows remote attackers to execute arbitr
KritikCVSS 9,8İstismar yokEPSS %2monstra · monstra17 Haz 2021
- CVE-2018-1167840Planlayın
plugins/box/users/users.plugin.php in Monstra CMS 3.0.4 allows Login Rate Limiting Bypass via manipulation of the login_attempts cookie.
KritikCVSS 9,8İstismar yokEPSS %2monstra · monstra cms5 Haz 2018
- CVE-2018-638339İzleyin
Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .pha
YüksekCVSS 8,8Kavram kanıtıEPSS %13monstra · monstra29 Oca 2018
- CVE-2021-4094039İzleyin
Monstra 3.0.4 does not filter the case of php, which leads to an unrestricted file upload vulnerability.
KritikCVSS 9,8İstismar yokEPSS %2monstra · monstra15 Haz 2022
- CVE-2018-903736İzleyin
Monstra CMS 3.0.4 allows remote code execution via an upload_file request for a .zip file, which is automatically extracted and may contain
YüksekCVSS 8,8İstismar yokEPSS %3monstra · monstra10 Nis 2018
- CVE-2020-1338436İzleyin
Monstra CMS 3.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via admin/index.php?id=filesmanager because, fo
YüksekCVSS 8,8İstismar yokEPSS %3monstra · monstra22 May 2020
- CVE-2020-2321935İzleyin
Monstra CMS 3.0.4 allows attackers to execute arbitrary code via a crafted payload entered into the "Snippet content" field under the "Edit
YüksekCVSS 8,8İstismar yokEPSS %2monstra · monstra cms1 Tem 2021
- CVE-2018-1660835İzleyin
In Monstra CMS 3.0.4, an attacker with 'Editor' privileges can change the password of the administrator via an admin/index.php?id=users&acti
YüksekCVSS 8,8İstismar yokEPSS %1monstra · monstra10 Eyl 2018
- CVE-2025-6990635İzleyin
Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin.
YüksekCVSS 8,8Kavram kanıtıEPSS %1monstra · monstra cms5 Şub 2026
- CVE-2018-1147432İzleyin
Monstra CMS 3.0.4 has a Session Management Issue in the Administrations Tab.
YüksekCVSS 8,0İstismar yokEPSS %1monstra · monstra25 May 2018
- CVE-2018-1147532İzleyin
Monstra CMS 3.0.4 has a Session Management Issue in the Users tab.
YüksekCVSS 8,0İstismar yokEPSS %1monstra · monstra25 May 2018
- CVE-2018-1682031İzleyin
admin/index.php in Monstra CMS 3.0.4 allows arbitrary directory listing via id=filesmanager&path=uploads/.......//./.......//./ requests.
YüksekCVSS 7,5İstismar yokEPSS %2monstra · monstra18 Eyl 2018
- CVE-2018-903829İzleyin
Monstra CMS 3.0.4 allows remote attackers to delete files via an admin/index.php?id=filesmanager&delete_dir=./&path=uploads/ request.
OrtaCVSS 6,5Kavram kanıtıEPSS %9monstra · monstra10 Nis 2018
- CVE-2018-1741829İzleyin
Monstra CMS 3.0.4 allows remote attackers to execute arbitrary PHP code via a mixed-case file extension, as demonstrated by the 123.PhP file
YüksekCVSS 7,2Kavram kanıtıEPSS %3monstra · monstra7 Mar 2019
- CVE-2018-1588628İzleyin
Monstra CMS 3.0.4 does not properly restrict modified Snippet content, as demonstrated by the admin/index.php?id=snippets&action=edit_snippe
YüksekCVSS 7,2İstismar yokEPSS %2monstra · monstra10 Eyl 2018
- CVE-2020-1397828İzleyin
Monstra CMS 3.0.4 allows an attacker, who already has administrative access to modify .chunk.php files on the Edit Chunk screen, to execute
YüksekCVSS 7,2İstismar yokEPSS %1monstra · monstra cms9 Haz 2020
- CVE-2024-3677428İzleyin
An arbitrary file upload vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.
YüksekCVSS 7,2İstismar yokEPSS %1monstra · monstra6 Haz 2024
- CVE-2020-843926İzleyin
Monstra CMS through 3.0.4 allows remote authenticated users to take over arbitrary user accounts via a modified login parameter to an edit U
OrtaCVSS 6,5İstismar yokEPSS %2monstra · monstra6 Mar 2020
- CVE-2020-2069126İzleyin
An issue in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via bypassing the file extension filter and uploadi
OrtaCVSS 6,5İstismar yokEPSS %1monstra · monstra cms27 Eyl 2021
- CVE-2018-1122725İzleyin
Monstra CMS 3.0.4 and earlier has XSS via index.php.
OrtaCVSS 6,1Kavram kanıtıEPSS %5monstra · monstra cms3 Tem 2019
- CVE-2018-1697925İzleyin
Monstra CMS V3.0.4 allows HTTP header injection in the plugins/captcha/crypt/cryptographp.php cfg parameter, a related issue to CVE-2012-294
OrtaCVSS 6,1Kavram kanıtıEPSS %3monstra · monstra12 Eyl 2018
- CVE-2018-1147325İzleyin
Monstra CMS 3.0.4 has XSS in the registration Form (i.e., the login parameter to users/registration).
OrtaCVSS 6,1Kavram kanıtıEPSS %2monstra · monstra25 May 2018
- CVE-2018-1492225İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Monstra CMS 3.0.4 allow remote attackers to inject arbitrary web script or HTML via t
OrtaCVSS 6,1İstismar yokEPSS %2monstra · monstra14 Ağu 2018