Monstaftp
Monstaftp Monsta FTP: vulnerabilidades y CVE
Monstaftp Monsta FTP tiene 7 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses2
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-60105 | Alta (7.7) | 1.5% | — | 8 jul 2026 | Monsta FTP before 2.14.5 contains a server-side request forgery vulnerability in the fetchRemoteFile action caused by an incomplete IP blocklist check in the isBlockedIP() function, which fails to detect embedded IPv4… |
| CVE-2025-34299 | Crítica (9.3) | 73% | — | 7 nov 2025 | Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers to execute arbitrary code by uploading a specially crafted file from a… |
| CVE-2022-27469 | Crítica (9.8) | 1.4% | — | 26 abr 2022 | Monstaftp v2.10.3 was discovered to allow attackers to execute Server-Side Request Forgery (SSRF). |
| CVE-2022-27468 | Crítica (9.8) | 2.1% | — | 26 abr 2022 | Monstaftp v2.10.3 was discovered to contain an arbitrary file upload which allows attackers to execute arbitrary code via a crafted file uploaded to the web server. |
| CVE-2020-14057 | Crítica (9.8) | 2.6% | — | 1 jul 2020 | Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations. This allows attackers to read and write arbitrary local files, allowing an attacker to gain remote code execution in common… |
| CVE-2020-14056 | Crítica (9.8) | 1.3% | — | 1 jul 2020 | Monsta FTP 2.10.1 or below is prone to a server-side request forgery vulnerability due to insufficient restriction of the web fetch functionality. This allows attackers to read arbitrary local files and interact with… |
| CVE-2020-14055 | Media (6.1) | 0.70% | — | 1 jul 2020 | Monsta FTP 2.10.1 or below is prone to a stored cross-site scripting vulnerability in the language setting due to insufficient output encoding. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.