CVE-2018-16977: Monstra

Medium severity, CVSS 5.3. EPSS: 1.2% chance of exploitation in the next 30 days.

Monstra CMS V3.0.4 has an information leakage risk (e.g., PATH, DOCUMENT_ROOT, and SERVER_ADMIN) in libraries/Gelato/ErrorHandler/Resources/Views/Errors/exception.php.

Affected products

  • Monstra Monstra: version 3.0.4 only

Published 2018-09-12. Last modified 2026-06-17.