← Vulnerability feed

Vulnerability record · CVE-2018-11678 · published 5 June 2018

CVE-2018-11678: Monstra cms improper input validation vulnerability

Monstra · Monstra Cms

plugins/box/users/users.plugin.php in Monstra CMS 3.0.4 allows Login Rate Limiting Bypass via manipulation of the login_attempts cookie.

9.8 CVSS 3.0 Critical EPSS 1.7% · top 24.0% CWE-20 · Improper input validation
9.8CVSS 3.0 base score, v2 5.0
1.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

plugins/box/users/users.plugin.php in Monstra CMS 3.0.4 allows Login Rate Limiting Bypass via manipulation of the login_attempts cookie.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-11678 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2025-69906Monstra cms unrestricted file upload vulnerabilityMonstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin. The application relies on blacklist-based file extens…EPSS 0.72%8.8CVE-2020-23219Monstra cms code injection vulnerabilityMonstra CMS 3.0.4 allows attackers to execute arbitrary code via a crafted payload entered into the "Snippet content" field under the "Edit Snippet" …EPSS 1.6%7.2CVE-2020-13978Monstra cms os command injection vulnerabilityMonstra CMS 3.0.4 allows an attacker, who already has administrative access to modify .chunk.php files on the Edit Chunk screen, to execute arbitrary…EPSS 1.3%6.5CVE-2020-20691Monstra cms unrestricted file upload vulnerabilityAn issue in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via bypassing the file extension filter and uploading crafte…EPSS 0.93%6.1CVE-2018-11227Monstra cms cross-site scripting vulnerabilityMonstra CMS 3.0.4 and earlier has XSS via index.php.EPSS 4.7%5.4CVE-2020-23697Monstra cms cross-site scripting vulnerabilityCross Site Scripting vulnerabilty in Monstra CMS 3.0.4 via the page feature in admin/index.php.EPSS 1.9%5.4CVE-2020-23205Monstra cms cross-site scripting vulnerabilityA stored cross site scripting (XSS) vulnerability in Monstra CMS version 3.0.4 allows attackers to execute arbitrary web scripts or HTML via crafted …EPSS 0.53%5.4CVE-2018-19599Monstra cms cross-site scripting vulnerabilityMonstra CMS 1.6 allows XSS via an uploaded SVG document to the admin/index.php?id=filesmanager&path=uploads/ URI. NOTE: this is a discontinued produc…EPSS 0.73%

Source: NIST National Vulnerability Database (record CVE-2018-11678), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.