Monster menus
This hub aggregates every CVE we track for Monster menus, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
6
CVEs tracked
1
Critical
0
High
0
In CISA KEV
Severity distribution
MEDIUM3LOW2CRITICAL1
Monthly trend
0
0
0
0
0
2
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-082026-07
Latest CVEs
The 6 most recently published vulnerabilities affecting Monster menus.
- CVE-2024-13288Monster Menus - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-0524.3
- CVE-2024-13281Monster Menus - Moderately critical - Access bypass, Information Disclosure - SA-CONTRIB-2024-0459.1
- CVE-2015-8095The recycle bin feature in the Monster Menus module 7.x-1.21 before 7.x-1.24 for Drupal does not properly remove nodes from view, which allows remote attackers to obtain sensitive information via a...5.0
- CVE-2013-4504The Monster Menus module 7.x-1.x before 7.x-1.15 allows remote attackers to read arbitrary node comments via a crafted URL.2.6
- CVE-2013-4230The mm_webform submodule in the Monster Menus module 6.x-6.x before 6.x-6.61 and 7.x-1.x before 7.x-1.13 for Drupal does not properly restrict access to webform submissions, which allows remote aut...6.0
- CVE-2013-4229Cross-site scripting (XSS) vulnerability in the Monster Menus module 7.x-1.x before 7.x-1.12 for Drupal allows remote authenticated users with permissions to add pages to inject arbitrary web scrip...2.1
Product normalization is registry-driven with AI assist and human review. How it works