VYPR

Monstra

by Monstra

CVEs (2)

  • CVE-2025-69906Feb 5, 2026
    risk 0.00cvss epss 0.00

    Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin. The application relies on blacklist-based file extension validation and stores uploaded files directly in a web-accessible directory. Under typical server configurations, this can allow an attacker to upload files that are interpreted as executable code, resulting in remote code execution.

  • CVE-2014-9006Nov 20, 2014
    risk 0.00cvss epss 0.00

    Monstra 3.0.1 and earlier uses a cookie to track how many login attempts have been attempted, which allows remote attackers to conduct brute force login attacks by deleting the login_attempts cookie or setting it to certain values.