← Vulnerability feed

Vulnerability record · CVE-2020-25414 · published 17 June 2021

CVE-2020-25414: Monstra inclusion from untrusted sphere vulnerability

Monstra · Monstra

A local file inclusion vulnerability was discovered in the captcha function in Monstra 3.0.4 which allows remote attackers to execute arbitrary PHP code.

9.8 CVSS 3.1 Critical EPSS 2.0% · top 19.7% CWE-829 · Inclusion from untrusted sphere
9.8CVSS 3.1 base score, v2 7.5
2.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A local file inclusion vulnerability was discovered in the captcha function in Monstra 3.0.4 which allows remote attackers to execute arbitrary PHP code.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/monstra-cms/monstra/issues/469 ExploitIssue TrackingThird Party Advisory
https://github.com/monstra-cms/monstra/issues/469 ExploitIssue TrackingThird Party Advisory

Track CVE-2020-25414 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-40940Monstra unrestricted file upload vulnerabilityMonstra 3.0.4 does not filter the case of php, which leads to an unrestricted file upload vulnerability.EPSS 1.6%9.8CVE-2021-36548Monstra unrestricted file upload vulnerabilityA remote code execution (RCE) vulnerability in the component /admin/index.php?id=themes&action=edit_template&filename=blog of Monstra v3.0.4 allows a…EPSS 3.3%8.8CVE-2020-13384Monstra unrestricted file upload vulnerabilityMonstra CMS 3.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via admin/index.php?id=filesmanager because, for example…EPSS 2.5%8.8CVE-2018-16608Monstra insecure direct object reference vulnerabilityIn Monstra CMS 3.0.4, an attacker with 'Editor' privileges can change the password of the administrator via an admin/index.php?id=users&action=edit&u…EPSS 1.2%8.8CVE-2018-9037Monstra unrestricted file upload vulnerabilityMonstra CMS 3.0.4 allows remote code execution via an upload_file request for a .zip file, which is automatically extracted and may contain .php file…EPSS 2.8%8.8CVE-2018-6383Monstra vulnerabilityMonstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .phar extensi…EPSS 13%8.8CVE-2017-18048Monstra CMS case-sensitive extension check allows arbitrary file upload RCEMonstra CMS 3.0.4 blocks the lowercase .php extension on uploads but not the uppercase .PHP, so an authenticated user can upload a PHP file that the …EPSS 63%analysed8.0CVE-2018-11474Monstra vulnerabilityMonstra CMS 3.0.4 has a Session Management Issue in the Administrations Tab. A password change at admin/index.php?id=users&action=edit&user_id=1 does…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2020-25414), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.