CVE-2020-20691: Monstra CMS

Medium severity, CVSS 6.5. EPSS: 0.9% chance of exploitation in the next 30 days.

An issue in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via bypassing the file extension filter and uploading crafted HTML files.

Affected products

  • Monstra Monstra CMS: version 3.0.4 only

Published 2021-09-27. Last modified 2026-06-17.