Monstra CMS before 3.0.4 has XSS via index.php.
EPSS
6.1 Medium
CVSS3
CVE-2018-11227
Monstra CMS 3.0.4 and earlier has XSS via index.php.