Monstra 3.0.4 does not filter the case of php, which leads to an unrestricted file upload vulnerability.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-40940.json"