← Back

Monstra

monstra

Vendor: Monstra • 34 CVEs

CVEs (34)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Monstra
1Monstra
Nov 21, 2024
Jun 7, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Themes parameter at index.php.
1Monstra
1Monstra
Nov 21, 2024
Jun 6, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the About Me parameter in the Edit Profile page.
1Monstra
1Monstra
Nov 21, 2024
Jun 6, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
An arbitrary file upload vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.
1Monstra
1Monstra
Nov 21, 2024
Jun 15, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Monstra 3.0.4 does not filter the case of php, which leads to an unrestricted file upload vulnerability.
1Monstra
1Monstra
Nov 21, 2024
Oct 28, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A remote code execution (RCE) vulnerability in the component /admin/index.php?id=themes&action=edit_template&filename=blog of Monstra v3.0.4 allows attackers to execute arbitrary commands via a crafted PHP file.
1Monstra
1Monstra
Nov 21, 2024
Jun 17, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A local file inclusion vulnerability was discovered in the captcha function in Monstra 3.0.4 which allows remote attackers to execute arbitrary PHP code.
1Monstra
1Monstra
Nov 21, 2024
May 22, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Monstra CMS 3.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via admin/index.php?id=filesmanager because, for example, .php filenames are blocked but .php7 filenames are not, a related iss...Show more
Monstra CMS 3.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via admin/index.php?id=filesmanager because, for example, .php filenames are blocked but .php7 filenames are not, a related issue to CVE-2017-18048.Show less
1Monstra
1Monstra
Nov 21, 2024
Mar 7, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Monstra CMS through 3.0.4 allows remote authenticated users to take over arbitrary user accounts via a modified login parameter to an edit URI, as demonstrated by login=victim to the users/21/edit URI.
1Monstra
1Monstra
Nov 21, 2024
Mar 7, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Monstra CMS 3.0.4 allows remote attackers to execute arbitrary PHP code via a mixed-case file extension, as demonstrated by the 123.PhP filename, because plugins\box\filesmanager\filesmanager.admin.php mishandles the for...Show more
Monstra CMS 3.0.4 allows remote attackers to execute arbitrary PHP code via a mixed-case file extension, as demonstrated by the 123.PhP filename, because plugins\box\filesmanager\filesmanager.admin.php mishandles the forbidden_types variable.Show less
1Monstra
1Monstra
Nov 21, 2024
Oct 29, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
admin/index.php?id=filesmanager in Monstra CMS 3.0.4 allows remote authenticated administrators to trigger stored XSS via JavaScript content in a file whose name lacks an extension. Such a file is interpreted as text/htm...Show more
admin/index.php?id=filesmanager in Monstra CMS 3.0.4 allows remote authenticated administrators to trigger stored XSS via JavaScript content in a file whose name lacks an extension. Such a file is interpreted as text/html in certain cases.Show less
1Monstra
1Monstra
Nov 21, 2024
Sep 18, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
admin/index.php in Monstra CMS 3.0.4 allows arbitrary directory listing via id=filesmanager&path=uploads/.......//./.......//./ requests.
1Monstra
1Monstra
Nov 21, 2024
Sep 18, 2018
N/A· v4
4.9 MEDIUM· v3
5.5 MEDIUM· v2
admin/index.php in Monstra CMS 3.0.4 allows arbitrary file deletion via id=filesmanager&path=uploads/.......//./.......//./&delete_file= requests.
1Monstra
1Monstra
Nov 21, 2024
Sep 13, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an edit_page&name=error404 action, a different vulnerability than CVE-2018-10121.
1Monstra
1Monstra
Nov 21, 2024
Sep 13, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an edit_page action for a page with no special role.
1Monstra
1Monstra
Nov 21, 2024
Sep 13, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an add_page action.
1Monstra
1Monstra
Nov 21, 2024
Sep 12, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Monstra CMS V3.0.4 allows HTTP header injection in the plugins/captcha/crypt/cryptographp.php cfg parameter, a related issue to CVE-2012-2943.
1Monstra
1Monstra
Nov 21, 2024
Sep 12, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Monstra CMS V3.0.4 has XSS when ones tries to register an account with a crafted password parameter to users/registration, a different vulnerability than CVE-2018-11473.
1Monstra
1Monstra
Nov 21, 2024
Sep 12, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Monstra CMS V3.0.4 has an information leakage risk (e.g., PATH, DOCUMENT_ROOT, and SERVER_ADMIN) in libraries/Gelato/ErrorHandler/Resources/Views/Errors/exception.php.
1Monstra
1Monstra
Nov 21, 2024
Sep 10, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
In Monstra CMS 3.0.4, an attacker with 'Editor' privileges can change the password of the administrator via an admin/index.php?id=users&action=edit&user_id=1, Insecure Direct Object Reference (IDOR).
1Monstra
1Monstra
Nov 21, 2024
Sep 10, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Monstra CMS 3.0.4 does not properly restrict modified Snippet content, as demonstrated by the admin/index.php?id=snippets&action=edit_snippet&filename=google-analytics URI, which allows attackers to execute arbitrary PHP...Show more
Monstra CMS 3.0.4 does not properly restrict modified Snippet content, as demonstrated by the admin/index.php?id=snippets&action=edit_snippet&filename=google-analytics URI, which allows attackers to execute arbitrary PHP code by placing this code after a <?php substring.Show less