Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 06 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-434 | |
| Metrics |
cvssV3_1
|
Fri, 06 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Monstra
Monstra monstra Cms |
|
| Vendors & Products |
Monstra
Monstra monstra Cms |
Thu, 05 Feb 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin. The application relies on blacklist-based file extension validation and stores uploaded files directly in a web-accessible directory. Under typical server configurations, this can allow an attacker to upload files that are interpreted as executable code, resulting in remote code execution. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-02-06T15:57:50.945Z
Reserved: 2026-01-09T00:00:00.000Z
Link: CVE-2025-69906
Updated: 2026-02-06T15:54:42.050Z
Status : Undergoing Analysis
Published: 2026-02-05T17:16:12.900
Modified: 2026-02-06T16:16:14.713
Link: CVE-2025-69906
No data.
OpenCVE Enrichment
Updated: 2026-02-06T12:05:21Z