CVE-2020-25414: Monstra
Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.
A local file inclusion vulnerability was discovered in the captcha function in Monstra 3.0.4 which allows remote attackers to execute arbitrary PHP code.
Affected products
- Monstra Monstra: version 3.0.4 only
Published 2021-06-17. Last modified 2026-06-17.