Monstra CMS 3.0.4 and earlier has XSS via index.php.
- https://github.com/monstra-cms/monstra/issues
- https://www.exploit-db.com/exploits/44646
- https://github.com/ARPSyndicate/kenzer-templates