Home/Product/totaljs total.js
Product

totaljs total.js

26 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-11019
< 19.9.0
A vulnerability has been found in Total.js CMS up to 19.9.0. This impacts an unknown function of the component Files Menu. The man
2.4LOW
CVE-2025-10940
all versions
A vulnerability was found in Total.js CMS 1.0.0. Affected by this vulnerability is the function layouts_save of the file /admin/ o
2.4LOW
CVE-2024-48655
all versions
An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file.
8.8HIGH
CVE-2023-30097
all versions
A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web sc
5.4MEDIUM
CVE-2023-30096
all versions
A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web sc
5.4MEDIUM
CVE-2023-30095
all versions
A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web sc
5.4MEDIUM
CVE-2023-30094
all versions
A stored cross-site scripting (XSS) vulnerability in TotalJS Flow v10 allows attackers to execute arbitrary web scripts or HTML vi
5.4MEDIUM
CVE-2023-27070
all versions
A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web
5.4MEDIUM
CVE-2023-27069
all versions
A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web
5.4MEDIUM
CVE-2022-44019
< 2022-09-26
In Total.js 4 before 0e5ace7, /api/common/ping can achieve remote command execution via shell metacharacters in the host parameter
8.8HIGH
CVE-2022-41392
all versions
A cross-site scripting (XSS) vulnerability in TotalJS commit 8c2c8909 allows attackers to execute arbitrary web scripts or HTML vi
5.4MEDIUM
CVE-2022-30013
all versions
A stored cross-site scripting (XSS) vulnerability in the upload function of totaljs CMS 3.4.5 allows attackers to execute arbitrar
5.4MEDIUM
CVE-2022-26565
< 2022-02-28
A cross-site scripting (XSS) vulnerability in Totaljs all versions before commit 95f54a5commit, allows attackers to execute arbitr
4.8MEDIUM
CVE-2021-32831
< 3.4.9
Total.js framework (npm package total.js) is a framework for Node.js platfrom written in pure JavaScript similar to PHP's Laravel
7.5HIGH
CVE-2021-23390
< 0.0.43
The package total4 before 0.0.43 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.
9.8CRITICAL
CVE-2021-23389
< 3.4.9
The package total.js before 3.4.9 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.
9.8CRITICAL
CVE-2021-23344
< 3.4.8
The package total.js before 3.4.8 are vulnerable to Remote Code Execution (RCE) via set.
9.8CRITICAL
CVE-2020-28495
< 3.4.7
This affects the package total.js before 3.4.7. The set function can be used to set a value into the object according to the path.
7.3HIGH
CVE-2020-28494
< 3.4.7
This affects the package total.js before 3.4.7. The issue occurs in the image.pipe and image.stream functions. The type parameter
8.6HIGH
CVE-2020-9381
all versions
controllers/admin.js in Total.js CMS 13 allows remote attackers to execute arbitrary code via a POST to the /admin/api/widgets/ UR
7.5HIGH
CVE-2019-15955
all versions
An issue was discovered in Total.js CMS 12.0.0. A low privilege user can perform a simple transformation of a cookie to obtain the
6.5MEDIUM
CVE-2019-15954
all versions
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote Command E
9.9CRITICAL
CVE-2019-15953
all versions
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with limited privileges can get access to a resource that th
8.8HIGH
CVE-2019-15952
all versions
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the Pages privilege can conduct a path traversal attack
8.8HIGH
CVE-2019-10260
all versions
Total.js CMS 12.0.0 has XSS related to themes/admin/views/index.html (item.message) and themes/admin/public/ui.js (column.format).
6.1MEDIUM
CVE-2019-8903
< 3.2.3
index.js in Total.js Platform before 3.2.3 allows path traversal.
7.5HIGH
threatengine.sh