totaljs records
26 published records for vendor totaljs.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 2 · 7.7%
- Pre-auth RCE
- 6
- With a fix record
- 34.6%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-94 Improper Control of Generation of Code ('Code Injection')5
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-862 Missing Authorization2
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
The weakness classes this vendor ships most often: where to look.
CWEAll records
26 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
63This week | CVE-2019-15954Weaponized | An issue was discovered in Total.js CMS 12.0.0.totaljs · total.js cms · CWE-862 | Critical9.9 | — | 78.7% | Sep 5, 2019 |
52Plan | CVE-2019-8903Weaponized | index.js in Total.js Platform before 3.2.3 allows path traversal.totaljs · total.js · CWE-22 | High7.5 | — | 72.1% | Feb 18, 2019 |
40Plan | CVE-2021-23344No exploit | Remote Code Execution (RCE)totaljs · total.js · CWE-94 | Critical9.8 | — | 4.9% | Mar 4, 2021 |
40Plan | CVE-2021-23389No exploit | Arbitrary Code Executiontotaljs · total.js · CWE-94 | Critical9.8 | — | 3.6% | Jul 12, 2021 |
40Plan | CVE-2021-23390No exploit | Arbitrary Code Executiontotaljs · total4 · CWE-94 | Critical9.8 | — | 3.0% | Jul 12, 2021 |
37Monitor | CVE-2019-15952No exploit | An issue was discovered in Total.js CMS 12.0.0.totaljs · total.js cms · CWE-22 | High8.8 | — | 5.1% | Sep 5, 2019 |
36Monitor | CVE-2022-44019No exploit | In Total.js 4 before 0e5ace7, /api/common/ping can achieve remote command execution via shell metacharacters in the host parameter.totaljs · total.js · CWE-78 | High8.8 | — | 2.2% | Oct 29, 2022 |
35Monitor | CVE-2020-28494No exploit | This affects the package total.js before 3.4.7.totaljs · total.js · CWE-78 | High8.6 | — | 1.7% | Feb 2, 2021 |
35Monitor | CVE-2019-15953No exploit | An issue was discovered in Total.js CMS 12.0.0.totaljs · total.js cms · CWE-862 | High8.8 | — | 1.5% | Sep 5, 2019 |
35Monitor | CVE-2024-48655No exploit | An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file.totaljs · total.js · CWE-94 | High8.8 | — | 1.0% | Oct 25, 2024 |
31Monitor | CVE-2020-9381No exploit | controllers/admin.js in Total.js CMS 13 allows remote attackers to execute arbitrary code via a POST to the /admin/api/widgets/ URI.totaljs · total.js cms · CWE-863 | High7.5 | — | 2.1% | Feb 24, 2020 |
30Monitor | CVE-2020-28495No exploit | This affects the package total.js before 3.4.7.totaljs · total.js | High7.3 | — | 3.6% | Feb 2, 2021 |
28Monitor | CVE-2021-32831No exploit | Code injection in total.jstotaljs · total.js · CWE-94 | High7.2 | — | 1.5% | Aug 30, 2021 |
26Monitor | CVE-2019-15955No exploit | An issue was discovered in Total.js CMS 12.0.0.totaljs · total.js cms · CWE-327 | Medium6.5 | — | 0.9% | Sep 5, 2019 |
24Monitor | CVE-2019-10260No exploit | Total.js CMS 12.0.0 has XSS related to themes/admin/views/index.html (item.message) and themes/admin/public/ui.js (column.format).totaljs · total.js cms · CWE-79 | Medium6.1 | — | 0.9% | Mar 28, 2019 |
21Monitor | CVE-2022-41392No exploit | A cross-site scripting (XSS) vulnerability in TotalJS commit 8c2c8909 allows attackers to execute arbitrary web scripts or HTML via a craftetotaljs · total.js · CWE-79 | Medium5.4 | — | 0.7% | Oct 7, 2022 |
21Monitor | CVE-2023-30095No exploit | A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or Htotaljs · messenger · CWE-79 | Medium5.4 | — | 0.7% | May 4, 2023 |
21Monitor | CVE-2023-30097No exploit | A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or Htotaljs · messenger · CWE-79 | Medium5.4 | — | 0.7% | May 4, 2023 |
21Monitor | CVE-2023-30096No exploit | A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or Htotaljs · messenger · CWE-79 | Medium5.4 | — | 0.7% | May 4, 2023 |
21Monitor | CVE-2023-30094No exploit | A stored cross-site scripting (XSS) vulnerability in TotalJS Flow v10 allows attackers to execute arbitrary web scripts or HTML via a craftetotaljs · flow · CWE-79 | Medium5.4 | — | 0.7% | May 4, 2023 |
21Monitor | CVE-2022-30013No exploit | A stored cross-site scripting (XSS) vulnerability in the upload function of totaljs CMS 3.4.5 allows attackers to execute arbitrary web scritotaljs · total.js · CWE-79 | Medium5.4 | — | 0.6% | May 16, 2022 |
21Monitor | CVE-2023-27070No exploit | A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts ototaljs · openplatform · CWE-79 | Medium5.4 | — | 0.5% | Mar 14, 2023 |
21Monitor | CVE-2023-27069No exploit | A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts ototaljs · openplatform · CWE-79 | Medium5.4 | — | 0.5% | Mar 14, 2023 |
19Monitor | CVE-2022-26565No exploit | A cross-site scripting (XSS) vulnerability in Totaljs all versions before commit 95f54a5commit, allows attackers to execute arbitrary web sctotaljs · content management system · CWE-79 | Medium4.8 | — | 0.5% | Apr 1, 2022 |
7Monitor | CVE-2025-10940No exploit | Total.js CMS Layout admin layouts_save cross site scriptingtotaljs · total.js · CWE-79 | Low1.9 | — | 0.3% | Sep 25, 2025 |
- CVE-2019-1595463This week
An issue was discovered in Total.js CMS 12.0.0.
CriticalCVSS 9.9WeaponizedEPSS 79%totaljs · total.js cmsSep 5, 2019
- CVE-2019-890352Plan
index.js in Total.js Platform before 3.2.3 allows path traversal.
HighCVSS 7.5WeaponizedEPSS 72%totaljs · total.jsFeb 18, 2019
- CVE-2021-2334440Plan
Remote Code Execution (RCE)
CriticalCVSS 9.8No exploitEPSS 5%totaljs · total.jsMar 4, 2021
- CVE-2021-2338940Plan
Arbitrary Code Execution
CriticalCVSS 9.8No exploitEPSS 4%totaljs · total.jsJul 12, 2021
- CVE-2021-2339040Plan
Arbitrary Code Execution
CriticalCVSS 9.8No exploitEPSS 3%totaljs · total4Jul 12, 2021
- CVE-2019-1595237Monitor
An issue was discovered in Total.js CMS 12.0.0.
HighCVSS 8.8No exploitEPSS 5%totaljs · total.js cmsSep 5, 2019
- CVE-2022-4401936Monitor
In Total.js 4 before 0e5ace7, /api/common/ping can achieve remote command execution via shell metacharacters in the host parameter.
HighCVSS 8.8No exploitEPSS 2%totaljs · total.jsOct 29, 2022
- CVE-2020-2849435Monitor
This affects the package total.js before 3.4.7.
HighCVSS 8.6No exploitEPSS 2%totaljs · total.jsFeb 2, 2021
- CVE-2019-1595335Monitor
An issue was discovered in Total.js CMS 12.0.0.
HighCVSS 8.8No exploitEPSS 2%totaljs · total.js cmsSep 5, 2019
- CVE-2024-4865535Monitor
An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file.
HighCVSS 8.8No exploitEPSS 1%totaljs · total.jsOct 25, 2024
- CVE-2020-938131Monitor
controllers/admin.js in Total.js CMS 13 allows remote attackers to execute arbitrary code via a POST to the /admin/api/widgets/ URI.
HighCVSS 7.5No exploitEPSS 2%totaljs · total.js cmsFeb 24, 2020
- CVE-2020-2849530Monitor
This affects the package total.js before 3.4.7.
HighCVSS 7.3No exploitEPSS 4%totaljs · total.jsFeb 2, 2021
- CVE-2021-3283128Monitor
Code injection in total.js
HighCVSS 7.2No exploitEPSS 1%totaljs · total.jsAug 30, 2021
- CVE-2019-1595526Monitor
An issue was discovered in Total.js CMS 12.0.0.
MediumCVSS 6.5No exploitEPSS 1%totaljs · total.js cmsSep 5, 2019
- CVE-2019-1026024Monitor
Total.js CMS 12.0.0 has XSS related to themes/admin/views/index.html (item.message) and themes/admin/public/ui.js (column.format).
MediumCVSS 6.1No exploitEPSS 1%totaljs · total.js cmsMar 28, 2019
- CVE-2022-4139221Monitor
A cross-site scripting (XSS) vulnerability in TotalJS commit 8c2c8909 allows attackers to execute arbitrary web scripts or HTML via a crafte
MediumCVSS 5.4No exploitEPSS 1%totaljs · total.jsOct 7, 2022
- CVE-2023-3009521Monitor
A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or H
MediumCVSS 5.4No exploitEPSS 1%totaljs · messengerMay 4, 2023
- CVE-2023-3009721Monitor
A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or H
MediumCVSS 5.4No exploitEPSS 1%totaljs · messengerMay 4, 2023
- CVE-2023-3009621Monitor
A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or H
MediumCVSS 5.4No exploitEPSS 1%totaljs · messengerMay 4, 2023
- CVE-2023-3009421Monitor
A stored cross-site scripting (XSS) vulnerability in TotalJS Flow v10 allows attackers to execute arbitrary web scripts or HTML via a crafte
MediumCVSS 5.4No exploitEPSS 1%totaljs · flowMay 4, 2023
- CVE-2022-3001321Monitor
A stored cross-site scripting (XSS) vulnerability in the upload function of totaljs CMS 3.4.5 allows attackers to execute arbitrary web scri
MediumCVSS 5.4No exploitEPSS 1%totaljs · total.jsMay 16, 2022
- CVE-2023-2707021Monitor
A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts o
MediumCVSS 5.4No exploitEPSS 1%totaljs · openplatformMar 14, 2023
- CVE-2023-2706921Monitor
A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts o
MediumCVSS 5.4No exploitEPSS 1%totaljs · openplatformMar 14, 2023
- CVE-2022-2656519Monitor
A cross-site scripting (XSS) vulnerability in Totaljs all versions before commit 95f54a5commit, allows attackers to execute arbitrary web sc
MediumCVSS 4.8No exploitEPSS 1%totaljs · content management systemApr 1, 2022
- CVE-2025-109407Monitor
Total.js CMS Layout admin layouts_save cross site scripting
LowCVSS 1.9No exploitEPSS 0%totaljs · total.jsSep 25, 2025