Monta has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was October 2026 with 4. The median CVSS is 7.4 (high), with 1 rated critical.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.4
- Publish → KEV
- —
- Last 90 days
- 4 prev 0
Worst active — by depth score
CVE-2026-95102Critical· 9.4WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations52CVE-2026-97363High· 7.5The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests41CVE-2026-97212High· 7.3The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier40CVE-2026-93474Medium· 6.5Charging station authentication identifiers are publicly accessible via web-based mapping platforms.36
Monta vulnerabilities
CVEs affecting Monta, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-97363High· 7.5The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks or brute-force attacks to gain unauthor…
CVE-2026-97212High· 7.3The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulne…
CVE-2026-95102Critical· 9.4WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized action…
CVE-2026-93474Medium· 6.5Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.