Monstra CMS 3.0.4 has Reflected XSS during Login (i.e., the login parameter to admin/index.php).
No PoCs from references.
- https://github.com/nikhil1232/Monstra-CMS-3.0.4-Reflected-XSS-On-Login-