Sploitus

CVE-2025-69906

2 known exploits for CVE-2025-69906

Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin. The application relies on blacklist-based file extension validation and stores uploaded files directly in a web-accessible directory. Under typical server configurations, this can allow an attacker to upload files that are interpreted as executable code, resulting in remote code execution.

Affected products
File Manager, Monstra Cms
Monstra Monstra Cms
= 3.0.4
CVSS 3.1
8.8 HIGH
EPSS
0.7% (51th percentile)
Weakness
CWE-434
NVD status
Analyzed
Published
2026-02-05
CVE-2025-69906 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2025-69906

Proof-of-concept code and exploit modules indexed by Sploitus