Totaljs / Total.js
12 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-11019 | Total.js CMS Files Menu cross site scripting | MEDIUM | 4.8 | Sep 26, 2025 |
| CVE-2025-10940 | Total.js CMS Layout admin layouts_save cross site scripting | MEDIUM | 4.8 | Sep 25, 2025 |
| CVE-2024-48655 | An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file. | HIGH | 8.8 | Oct 25, 2024 |
| CVE-2022-44019 | In Total.js 4 before 0e5ace7, /api/common/ping can achieve remote command execution via shell metacharacters in the host parameter. | HIGH | 8.8 | Oct 29, 2022 |
| CVE-2022-41392 | A cross-site scripting (XSS) vulnerability in TotalJS commit 8c2c8909 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected… | MEDIUM | 5.4 | Oct 7, 2022 |
| CVE-2022-30013 | A stored cross-site scripting (XSS) vulnerability in the upload function of totaljs CMS 3.4.5 allows attackers to execute arbitrary web scripts via a JavaScrip… | MEDIUM | 5.4 | May 16, 2022 |
| CVE-2021-32831 | Code injection in total.js | HIGH | 7.5 | Aug 30, 2021 |
| CVE-2021-23389 | Arbitrary Code Execution | CRITICAL | 9.8 | Jul 12, 2021 |
| CVE-2021-23344 | Remote Code Execution (RCE) | CRITICAL | 9.8 | Mar 4, 2021 |
| CVE-2020-28494 | Command Injection | HIGH | 8.6 | Feb 2, 2021 |
| CVE-2020-28495 | Prototype Pollution | HIGH | 7.3 | Feb 2, 2021 |
| CVE-2019-8903 | index.js in Total.js Platform before 3.2.3 allows path traversal. | HIGH | 7.5 | Feb 18, 2019 |
Showing 1 to 12 of 12 CVEs