CVE-2020-14056: Monstaftp Monsta FTP

Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.

Monsta FTP 2.10.1 or below is prone to a server-side request forgery vulnerability due to insufficient restriction of the web fetch functionality. This allows attackers to read arbitrary local files and interact with arbitrary third-party services.

Affected products

  • Monstaftp Monsta FTP: up to and including 2.10.1

Published 2020-07-01. Last modified 2026-06-17.