Vulnerabilities (CVE)

Filtered by vendor Monstra Subscribe
Filtered by product Monstra Cms
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-20691 1 Monstra 1 Monstra Cms 2021-10-08 5.8 MEDIUM 6.5 MEDIUM
An issue in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via bypassing the file extension filter and uploading crafted HTML files.
CVE-2020-23697 1 Monstra 1 Monstra Cms 2021-07-08 3.5 LOW 5.4 MEDIUM
Cross Site Scripting vulnerabilty in Monstra CMS 3.0.4 via the page feature in admin/index.php.
CVE-2020-23205 1 Monstra 1 Monstra Cms 2021-07-06 3.5 LOW 5.4 MEDIUM
A stored cross site scripting (XSS) vulnerability in Monstra CMS version 3.0.4 allows attackers to execute arbitrary web scripts or HTML via crafted a payload entered into the "Site Name" field under the "Site Settings" module.
CVE-2018-19599 1 Monstra 1 Monstra Cms 2020-06-24 3.5 LOW 5.4 MEDIUM
Monstra CMS 1.6 allows XSS via an uploaded SVG document to the admin/index.php?id=filesmanager&path=uploads/ URI. NOTE: this is a discontinued product.
CVE-2018-11227 1 Monstra 1 Monstra Cms 2019-07-08 4.3 MEDIUM 6.1 MEDIUM
Monstra CMS 3.0.4 and earlier has XSS via index.php.