CVE-2021-40940: Monstra

Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.

Monstra 3.0.4 does not filter the case of php, which leads to an unrestricted file upload vulnerability.

Affected products

  • Monstra Monstra: up to and including 3.0.4

Published 2022-06-15. Last modified 2026-06-17.