Total.js Cms
Totaljs · 7 CVEs
An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file.
Oct 25, 2024
controllers/admin.js in Total.js CMS 13 allows remote attackers to execute arbitrary code via a POST to the /admin/api/…
Feb 24, 2020
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the Pages privilege can conduct a path trave…
Sep 5, 2019
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with limited privileges can get access to a resou…
Sep 5, 2019
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remot…
Sep 5, 2019
An issue was discovered in Total.js CMS 12.0.0. A low privilege user can perform a simple transformation of a cookie to…
Sep 5, 2019
Total.js CMS 12.0.0 has XSS related to themes/admin/views/index.html (item.message) and themes/admin/public/ui.js (colu…
Mar 28, 2019
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2024-48655 | An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file. | HIGH | 1.03% | Oct 25, 2024 |
| CVE-2020-9381 | controllers/admin.js in Total.js CMS 13 allows remote attackers to execute arbitrary code via a POST to the /admin/api/widgets/ URI. This can be exploited in c… | HIGH | 2.11% | Feb 24, 2020 |
| CVE-2019-15952 | An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the Pages privilege can conduct a path traversal attack (../) to include .html files… | HIGH | 5.12% | Sep 5, 2019 |
| CVE-2019-15953 | An issue was discovered in Total.js CMS 12.0.0. An authenticated user with limited privileges can get access to a resource that they do not own by calling the… | HIGH | 1.55% | Sep 5, 2019 |
| CVE-2019-15954 | An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote Command Execution (RCE) on the remote… | CRITICAL | 78.69% | Sep 5, 2019 |
| CVE-2019-15955 | An issue was discovered in Total.js CMS 12.0.0. A low privilege user can perform a simple transformation of a cookie to obtain the random values inside it. If… | MEDIUM | 0.87% | Sep 5, 2019 |
| CVE-2019-10260 | Total.js CMS 12.0.0 has XSS related to themes/admin/views/index.html (item.message) and themes/admin/public/ui.js (column.format). | MEDIUM | 0.91% | Mar 28, 2019 |
Showing 1 to 7 of 7 CVEs