PT-2026-6595 · Unknown+1 · Monstra Cms+1

Published

2026-02-05

·

Updated

2026-02-06

·

CVE-2025-69906

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Monstra CMS version 3.0.4
Description Monstra CMS version 3.0.4’s Files Manager plugin has an issue where arbitrary files can be uploaded. The application uses a blacklist to validate file extensions and stores uploaded files in a directory accessible via the web. This could allow an attacker to upload files that are executed as code, leading to remote code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-69906

Affected Products

File Manager
Monstra Cms