VYPR
Vendor

Monkey CMS

Products
1
CVEs
13
Across products
13
Status
Private

Products

1

Recent CVEs

13
  • CVE-2025-63658HigJan 29, 2026
    risk 0.49cvss 7.5epss 0.01

    A stack overflow in the mk_http_index_lookup function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

  • CVE-2025-63657HigJan 29, 2026
    risk 0.49cvss 7.5epss 0.01

    An out-of-bounds read in the mk_mimetype_find function (mk_server/mk_mimetype.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

  • CVE-2025-63656HigJan 29, 2026
    risk 0.49cvss 7.5epss 0.01

    An out-of-bounds read in the header_cmp function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

  • CVE-2025-63655HigJan 29, 2026
    risk 0.49cvss 7.5epss 0.08

    A NULL pointer dereference in the mk_http_range_parse function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

  • CVE-2025-63653HigJan 29, 2026
    risk 0.49cvss 7.5epss 0.01

    An out-of-bounds read in the mk_vhost_fdt_close function (mk_server/mk_vhost.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

  • CVE-2025-63652HigJan 29, 2026
    risk 0.49cvss 7.5epss 0.01

    A use-after-free in the mk_http_request_end function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

  • CVE-2025-63651HigJan 29, 2026
    risk 0.49cvss 7.5epss 0.01

    A use-after-free in the mk_string_char_search function (mk_core/mk_string.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

  • CVE-2025-63650HigJan 29, 2026
    risk 0.49cvss 7.5epss 0.01

    An out-of-bounds read in the mk_ptr_to_buf in mk_core function (mk_memory.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

  • CVE-2025-63649HigJan 29, 2026
    risk 0.49cvss 7.5epss 0.01

    An out-of-bounds read in the http_parser_transfer_encoding_chunked function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted POST request to the server.

  • CVE-2013-3724Aug 1, 2013
    risk 0.04cvss epss 0.14

    The mk_request_header_process function in mk_request.c in Monkey 1.1.1 allows remote attackers to cause a denial of service (thread crash and service outage) via a '\0' character in an HTTP request.

  • CVE-2002-1852Dec 31, 2002
    risk 0.03cvss epss 0.03

    Cross-site scripting (XSS) vulnerability in Monkey 0.5.0 allows remote attackers to inject arbitrary web script or HTML via (1) the URL or (2) a parameter to test2.pl.

  • CVE-2014-5336Aug 26, 2014
    risk 0.00cvss epss 0.02

    Monkey HTTP Server before 1.5.3, when the File Descriptor Table (FDT) is enabled and custom error messages are set, allows remote attackers to cause a denial of service (file descriptor consumption) via an HTTP request that triggers an error message.

  • CVE-2007-2105Apr 18, 2007
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in admin/index.php in Monkey CMS 0.0.3 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the admin_skin parameter.