Vulnerabilities
7 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-34299 | Unauthenticated Arbitrary File Upload RCE in Monsta FTP 2.11 and earlier Monsta FTP versions 2.11 and earlier contain an unauthenticated arbitrary file upload flaw (CWE-434) that can be triggered remotely without any credentials or user interaction. An attacker can cause a specially crafted file to be uploaded from a malicious (S)FTP server that the Monsta FTP instance connects to, and the crafted upload ultimately allows execution of arbitrary code on the server hosting the web FTP client. Successful exploitation gives the attacker code execution with the privileges of the web application, which on typical shared hosting deployments can lead to compromise of hosted sites and stored credentials. Anyone running a self-hosted Monsta FTP instance at version 2.11 or earlier is affected, including instances embedded in hosting environments. A public proof-of-concept and technical write-up have been published by watchTowr Labs, the flaw is not yet listed in CISA KEV, and EPSS assigns a high 72.9% probability of exploitation within 30 days, indicating elevated near-term risk. Do: Upgrade Monsta FTP to the latest release newer than 2.11 as soon as a vendor-patched build is available, since the data does not specify a fixed version number. Until patched, restrict access to Monsta FTP (IP allow-listing, VPN, or an additional HTTP authentication layer in front of the application) and avoid connecting to untrusted (S)FTP servers. Review web server logs for unexpected or unauthenticated file writes/uploads and monitor watchTowr and vendor advisories for confirmation of in-the-wild exploitation. | 9.3 | 73% | PoC |
| nichelikely thousands to low tens of thousands of self-hosted instances (no public install counts available) | |
| CVE-2022-31827 | MonstaFTP v2.10.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the function performFetchRequest at HTTPFetcher.php. MonstaFTP v2.10.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the function performFetchRequest at HTTPFetcher.php. NVD description · AI analysis pending | 9.1 | 22% | PoC |
| — | |
| CVE-2022-27468 +1 in the same advisory: …27469 | Monstaftp v2.10.3 was discovered to contain an arbitrary file upload which allows attackers to execute arbitrary code via a crafted file uploaded to the web ser Monstaftp v2.10.3 was discovered to contain an arbitrary file upload which allows attackers to execute arbitrary code via a crafted file uploaded to the web server. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2020-14057 | Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations. Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations. This allows attackers to read and write arbitrary local files, allowing an attacker to gain remote code execution in common deployments. NVD description · AI analysis pending | 9.8 group max | 3% |
| — |