VYPR

Monstra

by Monstra

Source repositories

CVEs (43)

  • CVE-2018-17024MedSep 13, 2018
    risk 0.31cvss 4.8epss 0.01

    admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an add_page action.

  • CVE-2018-10121MedApr 16, 2018
    risk 0.31cvss 4.8epss 0.01

    plugins/box/pages/pages.admin.php in Monstra CMS 3.0.4 has a stored XSS vulnerability when an attacker has access to the editor role, and enters the payload in the title section of an admin/index.php?id=pages&action=edit_page&name=error404 (aka Edit 404 page) action.

  • CVE-2014-9006Nov 20, 2014
    risk 0.00cvss —epss 0.02

    Monstra 3.0.1 and earlier uses a cookie to track how many login attempts have been attempted, which allows remote attackers to conduct brute force login attacks by deleting the login_attempts cookie or setting it to certain values.

Page 3 of 3