Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Monstra

First CVE: Nov 20, 2014Active for: 12 yearsTotal CVEs: 43
47.7
VTI Score
High

Monstra is a content management system with a modestly represented but prominent vulnerability footprint that reflects its role as a self-hosted web application. Its disclosures cluster around a narrow product line and recur consistently through application-layer input and file-handling weaknesses: cross-site scripting, unrestricted file upload, path traversal, code injection, and session fixation. These weakness classes are characteristic of web frameworks where user input flows through code generation and file-system operations, and they reflect recurring defects in input neutralization and access boundaries rather than fundamental architectural flaws. The vendor's vulnerabilities skew toward a meaningful share of serious outcomes and frequently attract public exploit code, making timely patching important for any internet-exposed instance. Current exploitation activity, severity distribution, and exposure metrics are shown alongside this summary.

FAUCET AI Generated
43
Total CVEs
More Total CVEs than 98% of tracked vendors
2.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Monstra over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 20, 2014
11 years ago
Most Recent CVE
Feb 5, 2026
169 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (43 CVEs).

43 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-18048HIGH
Monstra CMS 3.0.4 allows users to upload arbitrary files, which leads to remote command execution on the server, for example because .php (lowercase) is blocked but .PHP (uppercase
Jan 23, 20188.873NOYES
CVE-2018-6383HIGH
Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .phar extension, which allows remote authent
Jan 29, 20188.846NOYES
CVE-2018-9038MEDIUM
Monstra CMS 3.0.4 allows remote attackers to delete files via an admin/index.php?id=filesmanager&delete_dir=./&path=uploads/ request.
Apr 10, 20186.536NOYES
CVE-2021-36548CRITICAL
A remote code execution (RCE) vulnerability in the component /admin/index.php?id=themes&action=edit_template&filename=blog of Monstra v3.0.4 allows attackers to execute arbitrary c
Oct 28, 20219.831NONO
CVE-2020-25414CRITICAL
A local file inclusion vulnerability was discovered in the captcha function in Monstra 3.0.4 which allows remote attackers to execute arbitrary PHP code.
Jun 17, 20219.831NONO
CVE-2018-11473MEDIUM
Monstra CMS 3.0.4 has XSS in the registration Form (i.e., the login parameter to users/registration).
May 25, 20186.131NOYES
CVE-2021-40940CRITICAL
Monstra 3.0.4 does not filter the case of php, which leads to an unrestricted file upload vulnerability.
Jun 15, 20229.830NONO
CVE-2018-11227MEDIUM
Monstra CMS 3.0.4 and earlier has XSS via index.php.
Jul 3, 20196.130NOYES
CVE-2018-16979MEDIUM
Monstra CMS V3.0.4 allows HTTP header injection in the plugins/captcha/crypt/cryptographp.php cfg parameter, a related issue to CVE-2012-2943.
Sep 12, 20186.130NOYES
CVE-2025-69906HIGH
Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin. The application relies on blacklist-based file extension validation and stores uploa
Feb 5, 20268.828NONO
View all 43 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products43 CVEs
58%
33%
9%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network42 (97.7%)
Unknown1 (2.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low42 (97.7%)
High0 (0.0%)
Unknown1 (2.3%)
User Interaction
None21 (48.8%)
Unknown1 (2.3%)
Required21 (48.8%)
Privileges Required
Low16 (37.2%)
High12 (27.9%)
None14 (32.6%)
Unknown1 (2.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (43 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
2.3% of CVEs· 97th percentile
Nuclei
4 CVEs
9.3% of CVEs· 96th percentile
ExploitDB
4 CVEs
9.3% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Monstra.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Monstra — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Monstra's Products

View all 1 CNAs →

Top CWEs