İçeriğe atla
Noroxi

totaljs kayıtları

totaljs üreticisine ait 26 yayımlanmış kayıt.

Tüm kayıtlar

26 kayıt
  • CVE-2019-15954
    63Bu hafta

    An issue was discovered in Total.js CMS 12.0.0.

    KritikCVSS 9,9SilahlaştırılmışEPSS %79

    totaljs · total.js cms5 Eyl 2019

  • CVE-2019-8903
    52Planlayın

    index.js in Total.js Platform before 3.2.3 allows path traversal.

    YüksekCVSS 7,5SilahlaştırılmışEPSS %72

    totaljs · total.js18 Şub 2019

  • CVE-2021-23344
    40Planlayın

    Remote Code Execution (RCE)

    KritikCVSS 9,8İstismar yokEPSS %5

    totaljs · total.js4 Mar 2021

  • CVE-2021-23389
    40Planlayın

    Arbitrary Code Execution

    KritikCVSS 9,8İstismar yokEPSS %4

    totaljs · total.js12 Tem 2021

  • CVE-2021-23390
    40Planlayın

    Arbitrary Code Execution

    KritikCVSS 9,8İstismar yokEPSS %3

    totaljs · total412 Tem 2021

  • CVE-2019-15952
    37İzleyin

    An issue was discovered in Total.js CMS 12.0.0.

    YüksekCVSS 8,8İstismar yokEPSS %5

    totaljs · total.js cms5 Eyl 2019

  • CVE-2022-44019
    36İzleyin

    In Total.js 4 before 0e5ace7, /api/common/ping can achieve remote command execution via shell metacharacters in the host parameter.

    YüksekCVSS 8,8İstismar yokEPSS %2

    totaljs · total.js29 Eki 2022

  • CVE-2020-28494
    35İzleyin

    This affects the package total.js before 3.4.7.

    YüksekCVSS 8,6İstismar yokEPSS %2

    totaljs · total.js2 Şub 2021

  • CVE-2019-15953
    35İzleyin

    An issue was discovered in Total.js CMS 12.0.0.

    YüksekCVSS 8,8İstismar yokEPSS %2

    totaljs · total.js cms5 Eyl 2019

  • CVE-2024-48655
    35İzleyin

    An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file.

    YüksekCVSS 8,8İstismar yokEPSS %1

    totaljs · total.js25 Eki 2024

  • CVE-2020-9381
    31İzleyin

    controllers/admin.js in Total.js CMS 13 allows remote attackers to execute arbitrary code via a POST to the /admin/api/widgets/ URI.

    YüksekCVSS 7,5İstismar yokEPSS %2

    totaljs · total.js cms24 Şub 2020

  • CVE-2020-28495
    30İzleyin

    This affects the package total.js before 3.4.7.

    YüksekCVSS 7,3İstismar yokEPSS %4

    totaljs · total.js2 Şub 2021

  • CVE-2021-32831
    28İzleyin

    Code injection in total.js

    YüksekCVSS 7,2İstismar yokEPSS %1

    totaljs · total.js30 Ağu 2021

  • CVE-2019-15955
    26İzleyin

    An issue was discovered in Total.js CMS 12.0.0.

    OrtaCVSS 6,5İstismar yokEPSS %1

    totaljs · total.js cms5 Eyl 2019

  • CVE-2019-10260
    24İzleyin

    Total.js CMS 12.0.0 has XSS related to themes/admin/views/index.html (item.message) and themes/admin/public/ui.js (column.format).

    OrtaCVSS 6,1İstismar yokEPSS %1

    totaljs · total.js cms28 Mar 2019

  • CVE-2022-41392
    21İzleyin

    A cross-site scripting (XSS) vulnerability in TotalJS commit 8c2c8909 allows attackers to execute arbitrary web scripts or HTML via a crafte

    OrtaCVSS 5,4İstismar yokEPSS %1

    totaljs · total.js7 Eki 2022

  • CVE-2023-30095
    21İzleyin

    A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or H

    OrtaCVSS 5,4İstismar yokEPSS %1

    totaljs · messenger4 May 2023

  • CVE-2023-30097
    21İzleyin

    A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or H

    OrtaCVSS 5,4İstismar yokEPSS %1

    totaljs · messenger4 May 2023

  • CVE-2023-30096
    21İzleyin

    A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or H

    OrtaCVSS 5,4İstismar yokEPSS %1

    totaljs · messenger4 May 2023

  • CVE-2023-30094
    21İzleyin

    A stored cross-site scripting (XSS) vulnerability in TotalJS Flow v10 allows attackers to execute arbitrary web scripts or HTML via a crafte

    OrtaCVSS 5,4İstismar yokEPSS %1

    totaljs · flow4 May 2023

  • CVE-2022-30013
    21İzleyin

    A stored cross-site scripting (XSS) vulnerability in the upload function of totaljs CMS 3.4.5 allows attackers to execute arbitrary web scri

    OrtaCVSS 5,4İstismar yokEPSS %1

    totaljs · total.js16 May 2022

  • CVE-2023-27070
    21İzleyin

    A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts o

    OrtaCVSS 5,4İstismar yokEPSS %1

    totaljs · openplatform14 Mar 2023

  • CVE-2023-27069
    21İzleyin

    A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts o

    OrtaCVSS 5,4İstismar yokEPSS %1

    totaljs · openplatform14 Mar 2023

  • CVE-2022-26565
    19İzleyin

    A cross-site scripting (XSS) vulnerability in Totaljs all versions before commit 95f54a5commit, allows attackers to execute arbitrary web sc

    OrtaCVSS 4,8İstismar yokEPSS %1

    totaljs · content management system1 Nis 2022

  • Total.js CMS Layout admin layouts_save cross site scripting

    DüşükCVSS 1,9İstismar yokEPSS %0

    totaljs · total.js25 Eyl 2025