Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 11 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:monstra:monstra_cms:3.0.4:*:*:*:*:*:*:* |
Fri, 06 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-434 | |
| Metrics |
cvssV3_1
|
Fri, 06 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Monstra
Monstra monstra Cms |
|
| Vendors & Products |
Monstra
Monstra monstra Cms |
Thu, 05 Feb 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin. The application relies on blacklist-based file extension validation and stores uploaded files directly in a web-accessible directory. Under typical server configurations, this can allow an attacker to upload files that are interpreted as executable code, resulting in remote code execution. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-02-06T15:57:50.945Z
Reserved: 2026-01-09T00:00:00.000Z
Link: CVE-2025-69906
Updated: 2026-02-06T15:54:42.050Z
Status : Analyzed
Published: 2026-02-05T17:16:12.900
Modified: 2026-02-11T19:07:15.937
Link: CVE-2025-69906
No data.
OpenCVE Enrichment
Updated: 2026-02-06T12:05:21Z