Monstra is a content management system with a modestly represented but prominent vulnerability footprint that reflects its role as a self-hosted web application. Its disclosures cluster around a narrow product line and recur consistently through application-layer input and file-handling weaknesses: cross-site scripting, unrestricted file upload, path traversal, code injection, and session fixation. These weakness classes are characteristic of web frameworks where user input flows through code generation and file-system operations, and they reflect recurring defects in input neutralization and access boundaries rather than fundamental architectural flaws. The vendor's vulnerabilities skew toward a meaningful share of serious outcomes and frequently attract public exploit code, making timely patching important for any internet-exposed instance. Current exploitation activity, severity distribution, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Monstra over time
Signals from CVEs in this vendor scope (43 CVEs).
43 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-18048HIGH Monstra CMS 3.0.4 allows users to upload arbitrary files, which leads to remote command execution on the server, for example because .php (lowercase) is blocked but .PHP (uppercase | Jan 23, 2018 | 8.8 | 73 | NO | YES |
CVE-2018-6383HIGH Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .phar extension, which allows remote authent | Jan 29, 2018 | 8.8 | 46 | NO | YES |
CVE-2018-9038MEDIUM Monstra CMS 3.0.4 allows remote attackers to delete files via an admin/index.php?id=filesmanager&delete_dir=./&path=uploads/ request. | Apr 10, 2018 | 6.5 | 36 | NO | YES |
CVE-2021-36548CRITICAL A remote code execution (RCE) vulnerability in the component /admin/index.php?id=themes&action=edit_template&filename=blog of Monstra v3.0.4 allows attackers to execute arbitrary c | Oct 28, 2021 | 9.8 | 31 | NO | NO |
CVE-2020-25414CRITICAL A local file inclusion vulnerability was discovered in the captcha function in Monstra 3.0.4 which allows remote attackers to execute arbitrary PHP code. | Jun 17, 2021 | 9.8 | 31 | NO | NO |
CVE-2018-11473MEDIUM Monstra CMS 3.0.4 has XSS in the registration Form (i.e., the login parameter to users/registration). | May 25, 2018 | 6.1 | 31 | NO | YES |
CVE-2021-40940CRITICAL Monstra 3.0.4 does not filter the case of php, which leads to an unrestricted file upload vulnerability. | Jun 15, 2022 | 9.8 | 30 | NO | NO |
CVE-2018-11227MEDIUM Monstra CMS 3.0.4 and earlier has XSS via index.php. | Jul 3, 2019 | 6.1 | 30 | NO | YES |
CVE-2018-16979MEDIUM Monstra CMS V3.0.4 allows HTTP header injection in the plugins/captcha/crypt/cryptographp.php cfg parameter, a related issue to CVE-2012-2943. | Sep 12, 2018 | 6.1 | 30 | NO | YES |
CVE-2025-69906HIGH Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin. The application relies on blacklist-based file extension validation and stores uploa | Feb 5, 2026 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (43 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Monstra.
Media articles that mention a CVE ID that affects a product developed by Monstra — matched by CVE ID, not by vendor name.