← Vulnerability feed

Vulnerability record · CVE-2020-20691 · published 27 September 2021

CVE-2020-20691: Monstra cms unrestricted file upload vulnerability

Monstra · Monstra Cms

An issue in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via bypassing the file extension filter and uploading crafted HTML files.

6.5 CVSS 3.1 Medium EPSS 0.93% · top 41.1% CWE-434 · Unrestricted file upload
6.5CVSS 3.1 base score, v2 5.8
0.93%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via bypassing the file extension filter and uploading crafted HTML files.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/monstra-cms/monstra/issues/461 ExploitIssue TrackingThird Party Advisory
https://github.com/monstra-cms/monstra/issues/461 ExploitIssue TrackingThird Party Advisory

Track CVE-2020-20691 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-11678Monstra cms improper input validation vulnerabilityplugins/box/users/users.plugin.php in Monstra CMS 3.0.4 allows Login Rate Limiting Bypass via manipulation of the login_attempts cookie.EPSS 1.7%8.8CVE-2025-69906Monstra cms unrestricted file upload vulnerabilityMonstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin. The application relies on blacklist-based file extens…EPSS 0.72%8.8CVE-2020-23219Monstra cms code injection vulnerabilityMonstra CMS 3.0.4 allows attackers to execute arbitrary code via a crafted payload entered into the "Snippet content" field under the "Edit Snippet" …EPSS 1.6%7.2CVE-2020-13978Monstra cms os command injection vulnerabilityMonstra CMS 3.0.4 allows an attacker, who already has administrative access to modify .chunk.php files on the Edit Chunk screen, to execute arbitrary…EPSS 1.3%6.1CVE-2018-11227Monstra cms cross-site scripting vulnerabilityMonstra CMS 3.0.4 and earlier has XSS via index.php.EPSS 4.7%5.4CVE-2020-23697Monstra cms cross-site scripting vulnerabilityCross Site Scripting vulnerabilty in Monstra CMS 3.0.4 via the page feature in admin/index.php.EPSS 1.9%5.4CVE-2020-23205Monstra cms cross-site scripting vulnerabilityA stored cross site scripting (XSS) vulnerability in Monstra CMS version 3.0.4 allows attackers to execute arbitrary web scripts or HTML via crafted …EPSS 0.53%5.4CVE-2018-19599Monstra cms cross-site scripting vulnerabilityMonstra CMS 1.6 allows XSS via an uploaded SVG document to the admin/index.php?id=filesmanager&path=uploads/ URI. NOTE: this is a discontinued produc…EPSS 0.73%

Source: NIST National Vulnerability Database (record CVE-2020-20691), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.