Monstaftp is a file-transfer management application with a narrow but prominent deployment footprint, and its vulnerability profile is characterized by web-facing input and upload-handling flaws that recur across its product line. The exposure skews strongly toward critical-severity outcomes and frequently acquires public exploit code, with weakness classes including server-side request forgery, unrestricted file uploads, cross-site scripting, and improper resource references that are typical of web applications processing untrusted client input. Defenders should treat Monstaftp instances as high-priority for patching and access control review; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Monstaftp over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-34299CRITICAL Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers to execute arbitrary code by uploading | Nov 7, 2025 | 9.8 | 88 | NO | YES |
CVE-2022-31827CRITICAL MonstaFTP v2.10.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the function performFetchRequest at HTTPFetcher.php. | Jun 9, 2022 | 9.1 | 38 | NO | NO |
CVE-2022-27468CRITICAL Monstaftp v2.10.3 was discovered to contain an arbitrary file upload which allows attackers to execute arbitrary code via a crafted file uploaded to the web server. | Apr 26, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-27469CRITICAL Monstaftp v2.10.3 was discovered to allow attackers to execute Server-Side Request Forgery (SSRF). | Apr 26, 2022 | 9.8 | 30 | NO | NO |
CVE-2020-14057CRITICAL Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations. This allows attackers to read and write arbitrary local files, allowing an attacker to ga | Jul 1, 2020 | 9.8 | 25 | NO | NO |
CVE-2020-14056CRITICAL Monsta FTP 2.10.1 or below is prone to a server-side request forgery vulnerability due to insufficient restriction of the web fetch functionality. This allows attackers to read arb | Jul 1, 2020 | 9.8 | 24 | NO | NO |
CVE-2020-14055MEDIUM Monsta FTP 2.10.1 or below is prone to a stored cross-site scripting vulnerability in the language setting due to insufficient output encoding. | Jul 1, 2020 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Monstaftp.
Media articles that mention a CVE ID that affects a product developed by Monstaftp — matched by CVE ID, not by vendor name.