CVE-2025-34299
Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers to execute arbitrary code by uploading a specially crafted file from a malicious (S)FTP server.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 72.85%
- CWE
- CWE-434
- Published
- 2025-11-07
- Last modified
- 2026-05-14
Affected products
- Monsta Limited of New Zealand Monsta FTP
Weakness type
Related vulnerabilities
- CVE-2026-87928 — MaxSite CMS 0.94 through 109.6 HTML Upload XSS via admin_page
- CVE-2026-26212 — Rara One Click Demo Import < 1.3.5 Arbitrary File Upload RCE
- CVE-2026-54611 — InstantCMS has Remote Code Execution in package installer
- CVE-2026-86666 — aircheng-org iWebShop-5 pic.php uploadFile unrestricted upload
- CVE-2026-50093 — A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173),...
- CVE-2026-86305 — light0011 cms Upload.class.php upload unrestricted upload
- CVE-2026-86272 — Beijing Meite Software Technology U+Smart Enjoyment WebSite UploadFormImg.ashx unrestricted upload
- CVE-2026-86239 — liufee FeehiCMS UEditor Widget UeditorAction.php init unrestricted upload