totaljs kayıtları
totaljs üreticisine ait 26 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 2 · %7,7
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %34,6
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-94 Improper Control of Generation of Code ('Code Injection')5
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-862 Missing Authorization2
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
26 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
63Bu hafta | CVE-2019-15954Silahlaştırılmış | An issue was discovered in Total.js CMS 12.0.0.totaljs · total.js cms · CWE-862 | Kritik9,9 | — | %78,7 | 5 Eyl 2019 |
52Planlayın | CVE-2019-8903Silahlaştırılmış | index.js in Total.js Platform before 3.2.3 allows path traversal.totaljs · total.js · CWE-22 | Yüksek7,5 | — | %72,1 | 18 Şub 2019 |
40Planlayın | CVE-2021-23344İstismar yok | Remote Code Execution (RCE)totaljs · total.js · CWE-94 | Kritik9,8 | — | %4,9 | 4 Mar 2021 |
40Planlayın | CVE-2021-23389İstismar yok | Arbitrary Code Executiontotaljs · total.js · CWE-94 | Kritik9,8 | — | %3,6 | 12 Tem 2021 |
40Planlayın | CVE-2021-23390İstismar yok | Arbitrary Code Executiontotaljs · total4 · CWE-94 | Kritik9,8 | — | %3,0 | 12 Tem 2021 |
37İzleyin | CVE-2019-15952İstismar yok | An issue was discovered in Total.js CMS 12.0.0.totaljs · total.js cms · CWE-22 | Yüksek8,8 | — | %5,1 | 5 Eyl 2019 |
36İzleyin | CVE-2022-44019İstismar yok | In Total.js 4 before 0e5ace7, /api/common/ping can achieve remote command execution via shell metacharacters in the host parameter.totaljs · total.js · CWE-78 | Yüksek8,8 | — | %2,2 | 29 Eki 2022 |
35İzleyin | CVE-2020-28494İstismar yok | This affects the package total.js before 3.4.7.totaljs · total.js · CWE-78 | Yüksek8,6 | — | %1,7 | 2 Şub 2021 |
35İzleyin | CVE-2019-15953İstismar yok | An issue was discovered in Total.js CMS 12.0.0.totaljs · total.js cms · CWE-862 | Yüksek8,8 | — | %1,5 | 5 Eyl 2019 |
35İzleyin | CVE-2024-48655İstismar yok | An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file.totaljs · total.js · CWE-94 | Yüksek8,8 | — | %1,0 | 25 Eki 2024 |
31İzleyin | CVE-2020-9381İstismar yok | controllers/admin.js in Total.js CMS 13 allows remote attackers to execute arbitrary code via a POST to the /admin/api/widgets/ URI.totaljs · total.js cms · CWE-863 | Yüksek7,5 | — | %2,1 | 24 Şub 2020 |
30İzleyin | CVE-2020-28495İstismar yok | This affects the package total.js before 3.4.7.totaljs · total.js | Yüksek7,3 | — | %3,6 | 2 Şub 2021 |
28İzleyin | CVE-2021-32831İstismar yok | Code injection in total.jstotaljs · total.js · CWE-94 | Yüksek7,2 | — | %1,5 | 30 Ağu 2021 |
26İzleyin | CVE-2019-15955İstismar yok | An issue was discovered in Total.js CMS 12.0.0.totaljs · total.js cms · CWE-327 | Orta6,5 | — | %0,9 | 5 Eyl 2019 |
24İzleyin | CVE-2019-10260İstismar yok | Total.js CMS 12.0.0 has XSS related to themes/admin/views/index.html (item.message) and themes/admin/public/ui.js (column.format).totaljs · total.js cms · CWE-79 | Orta6,1 | — | %0,9 | 28 Mar 2019 |
21İzleyin | CVE-2022-41392İstismar yok | A cross-site scripting (XSS) vulnerability in TotalJS commit 8c2c8909 allows attackers to execute arbitrary web scripts or HTML via a craftetotaljs · total.js · CWE-79 | Orta5,4 | — | %0,7 | 7 Eki 2022 |
21İzleyin | CVE-2023-30095İstismar yok | A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or Htotaljs · messenger · CWE-79 | Orta5,4 | — | %0,7 | 4 May 2023 |
21İzleyin | CVE-2023-30097İstismar yok | A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or Htotaljs · messenger · CWE-79 | Orta5,4 | — | %0,7 | 4 May 2023 |
21İzleyin | CVE-2023-30096İstismar yok | A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or Htotaljs · messenger · CWE-79 | Orta5,4 | — | %0,7 | 4 May 2023 |
21İzleyin | CVE-2023-30094İstismar yok | A stored cross-site scripting (XSS) vulnerability in TotalJS Flow v10 allows attackers to execute arbitrary web scripts or HTML via a craftetotaljs · flow · CWE-79 | Orta5,4 | — | %0,7 | 4 May 2023 |
21İzleyin | CVE-2022-30013İstismar yok | A stored cross-site scripting (XSS) vulnerability in the upload function of totaljs CMS 3.4.5 allows attackers to execute arbitrary web scritotaljs · total.js · CWE-79 | Orta5,4 | — | %0,6 | 16 May 2022 |
21İzleyin | CVE-2023-27070İstismar yok | A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts ototaljs · openplatform · CWE-79 | Orta5,4 | — | %0,5 | 14 Mar 2023 |
21İzleyin | CVE-2023-27069İstismar yok | A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts ototaljs · openplatform · CWE-79 | Orta5,4 | — | %0,5 | 14 Mar 2023 |
19İzleyin | CVE-2022-26565İstismar yok | A cross-site scripting (XSS) vulnerability in Totaljs all versions before commit 95f54a5commit, allows attackers to execute arbitrary web sctotaljs · content management system · CWE-79 | Orta4,8 | — | %0,5 | 1 Nis 2022 |
7İzleyin | CVE-2025-10940İstismar yok | Total.js CMS Layout admin layouts_save cross site scriptingtotaljs · total.js · CWE-79 | Düşük1,9 | — | %0,3 | 25 Eyl 2025 |
- CVE-2019-1595463Bu hafta
An issue was discovered in Total.js CMS 12.0.0.
KritikCVSS 9,9SilahlaştırılmışEPSS %79totaljs · total.js cms5 Eyl 2019
- CVE-2019-890352Planlayın
index.js in Total.js Platform before 3.2.3 allows path traversal.
YüksekCVSS 7,5SilahlaştırılmışEPSS %72totaljs · total.js18 Şub 2019
- CVE-2021-2334440Planlayın
Remote Code Execution (RCE)
KritikCVSS 9,8İstismar yokEPSS %5totaljs · total.js4 Mar 2021
- CVE-2021-2338940Planlayın
Arbitrary Code Execution
KritikCVSS 9,8İstismar yokEPSS %4totaljs · total.js12 Tem 2021
- CVE-2021-2339040Planlayın
Arbitrary Code Execution
KritikCVSS 9,8İstismar yokEPSS %3totaljs · total412 Tem 2021
- CVE-2019-1595237İzleyin
An issue was discovered in Total.js CMS 12.0.0.
YüksekCVSS 8,8İstismar yokEPSS %5totaljs · total.js cms5 Eyl 2019
- CVE-2022-4401936İzleyin
In Total.js 4 before 0e5ace7, /api/common/ping can achieve remote command execution via shell metacharacters in the host parameter.
YüksekCVSS 8,8İstismar yokEPSS %2totaljs · total.js29 Eki 2022
- CVE-2020-2849435İzleyin
This affects the package total.js before 3.4.7.
YüksekCVSS 8,6İstismar yokEPSS %2totaljs · total.js2 Şub 2021
- CVE-2019-1595335İzleyin
An issue was discovered in Total.js CMS 12.0.0.
YüksekCVSS 8,8İstismar yokEPSS %2totaljs · total.js cms5 Eyl 2019
- CVE-2024-4865535İzleyin
An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file.
YüksekCVSS 8,8İstismar yokEPSS %1totaljs · total.js25 Eki 2024
- CVE-2020-938131İzleyin
controllers/admin.js in Total.js CMS 13 allows remote attackers to execute arbitrary code via a POST to the /admin/api/widgets/ URI.
YüksekCVSS 7,5İstismar yokEPSS %2totaljs · total.js cms24 Şub 2020
- CVE-2020-2849530İzleyin
This affects the package total.js before 3.4.7.
YüksekCVSS 7,3İstismar yokEPSS %4totaljs · total.js2 Şub 2021
- CVE-2021-3283128İzleyin
Code injection in total.js
YüksekCVSS 7,2İstismar yokEPSS %1totaljs · total.js30 Ağu 2021
- CVE-2019-1595526İzleyin
An issue was discovered in Total.js CMS 12.0.0.
OrtaCVSS 6,5İstismar yokEPSS %1totaljs · total.js cms5 Eyl 2019
- CVE-2019-1026024İzleyin
Total.js CMS 12.0.0 has XSS related to themes/admin/views/index.html (item.message) and themes/admin/public/ui.js (column.format).
OrtaCVSS 6,1İstismar yokEPSS %1totaljs · total.js cms28 Mar 2019
- CVE-2022-4139221İzleyin
A cross-site scripting (XSS) vulnerability in TotalJS commit 8c2c8909 allows attackers to execute arbitrary web scripts or HTML via a crafte
OrtaCVSS 5,4İstismar yokEPSS %1totaljs · total.js7 Eki 2022
- CVE-2023-3009521İzleyin
A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or H
OrtaCVSS 5,4İstismar yokEPSS %1totaljs · messenger4 May 2023
- CVE-2023-3009721İzleyin
A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or H
OrtaCVSS 5,4İstismar yokEPSS %1totaljs · messenger4 May 2023
- CVE-2023-3009621İzleyin
A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or H
OrtaCVSS 5,4İstismar yokEPSS %1totaljs · messenger4 May 2023
- CVE-2023-3009421İzleyin
A stored cross-site scripting (XSS) vulnerability in TotalJS Flow v10 allows attackers to execute arbitrary web scripts or HTML via a crafte
OrtaCVSS 5,4İstismar yokEPSS %1totaljs · flow4 May 2023
- CVE-2022-3001321İzleyin
A stored cross-site scripting (XSS) vulnerability in the upload function of totaljs CMS 3.4.5 allows attackers to execute arbitrary web scri
OrtaCVSS 5,4İstismar yokEPSS %1totaljs · total.js16 May 2022
- CVE-2023-2707021İzleyin
A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts o
OrtaCVSS 5,4İstismar yokEPSS %1totaljs · openplatform14 Mar 2023
- CVE-2023-2706921İzleyin
A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts o
OrtaCVSS 5,4İstismar yokEPSS %1totaljs · openplatform14 Mar 2023
- CVE-2022-2656519İzleyin
A cross-site scripting (XSS) vulnerability in Totaljs all versions before commit 95f54a5commit, allows attackers to execute arbitrary web sc
OrtaCVSS 4,8İstismar yokEPSS %1totaljs · content management system1 Nis 2022
- CVE-2025-109407İzleyin
Total.js CMS Layout admin layouts_save cross site scripting
DüşükCVSS 1,9İstismar yokEPSS %0totaljs · total.js25 Eyl 2025