Skip to content
Noroxi

totaljs records

26 published records for vendor totaljs.

All records

26 records
  • CVE-2019-15954
    63This week

    An issue was discovered in Total.js CMS 12.0.0.

    CriticalCVSS 9.9WeaponizedEPSS 79%

    totaljs · total.js cmsSep 5, 2019

  • index.js in Total.js Platform before 3.2.3 allows path traversal.

    HighCVSS 7.5WeaponizedEPSS 72%

    totaljs · total.jsFeb 18, 2019

  • Remote Code Execution (RCE)

    CriticalCVSS 9.8No exploitEPSS 5%

    totaljs · total.jsMar 4, 2021

  • Arbitrary Code Execution

    CriticalCVSS 9.8No exploitEPSS 4%

    totaljs · total.jsJul 12, 2021

  • Arbitrary Code Execution

    CriticalCVSS 9.8No exploitEPSS 3%

    totaljs · total4Jul 12, 2021

  • An issue was discovered in Total.js CMS 12.0.0.

    HighCVSS 8.8No exploitEPSS 5%

    totaljs · total.js cmsSep 5, 2019

  • In Total.js 4 before 0e5ace7, /api/common/ping can achieve remote command execution via shell metacharacters in the host parameter.

    HighCVSS 8.8No exploitEPSS 2%

    totaljs · total.jsOct 29, 2022

  • This affects the package total.js before 3.4.7.

    HighCVSS 8.6No exploitEPSS 2%

    totaljs · total.jsFeb 2, 2021

  • An issue was discovered in Total.js CMS 12.0.0.

    HighCVSS 8.8No exploitEPSS 2%

    totaljs · total.js cmsSep 5, 2019

  • An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file.

    HighCVSS 8.8No exploitEPSS 1%

    totaljs · total.jsOct 25, 2024

  • CVE-2020-9381
    31Monitor

    controllers/admin.js in Total.js CMS 13 allows remote attackers to execute arbitrary code via a POST to the /admin/api/widgets/ URI.

    HighCVSS 7.5No exploitEPSS 2%

    totaljs · total.js cmsFeb 24, 2020

  • This affects the package total.js before 3.4.7.

    HighCVSS 7.3No exploitEPSS 4%

    totaljs · total.jsFeb 2, 2021

  • Code injection in total.js

    HighCVSS 7.2No exploitEPSS 1%

    totaljs · total.jsAug 30, 2021

  • An issue was discovered in Total.js CMS 12.0.0.

    MediumCVSS 6.5No exploitEPSS 1%

    totaljs · total.js cmsSep 5, 2019

  • Total.js CMS 12.0.0 has XSS related to themes/admin/views/index.html (item.message) and themes/admin/public/ui.js (column.format).

    MediumCVSS 6.1No exploitEPSS 1%

    totaljs · total.js cmsMar 28, 2019

  • A cross-site scripting (XSS) vulnerability in TotalJS commit 8c2c8909 allows attackers to execute arbitrary web scripts or HTML via a crafte

    MediumCVSS 5.4No exploitEPSS 1%

    totaljs · total.jsOct 7, 2022

  • A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or H

    MediumCVSS 5.4No exploitEPSS 1%

    totaljs · messengerMay 4, 2023

  • A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or H

    MediumCVSS 5.4No exploitEPSS 1%

    totaljs · messengerMay 4, 2023

  • A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or H

    MediumCVSS 5.4No exploitEPSS 1%

    totaljs · messengerMay 4, 2023

  • A stored cross-site scripting (XSS) vulnerability in TotalJS Flow v10 allows attackers to execute arbitrary web scripts or HTML via a crafte

    MediumCVSS 5.4No exploitEPSS 1%

    totaljs · flowMay 4, 2023

  • A stored cross-site scripting (XSS) vulnerability in the upload function of totaljs CMS 3.4.5 allows attackers to execute arbitrary web scri

    MediumCVSS 5.4No exploitEPSS 1%

    totaljs · total.jsMay 16, 2022

  • A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts o

    MediumCVSS 5.4No exploitEPSS 1%

    totaljs · openplatformMar 14, 2023

  • A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts o

    MediumCVSS 5.4No exploitEPSS 1%

    totaljs · openplatformMar 14, 2023

  • A cross-site scripting (XSS) vulnerability in Totaljs all versions before commit 95f54a5commit, allows attackers to execute arbitrary web sc

    MediumCVSS 4.8No exploitEPSS 1%

    totaljs · content management systemApr 1, 2022

  • Total.js CMS Layout admin layouts_save cross site scripting

    LowCVSS 1.9No exploitEPSS 0%

    totaljs · total.jsSep 25, 2025