Known Vulnerabilities for products from Totaljs

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Totaljs".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2025-11019 json A vulnerability has been found in Total.js CMS up to 19.9.0. This impacts an unknown function of the component Files Menu. Th... Not Provided 2025-09-26 2026-04-29
CVE-2025-10940 json A vulnerability was found in Total.js CMS 1.0.0. Affected by this vulnerability is the function layouts_save of the file /adm... Not Provided 2025-09-25 2026-04-29
CVE-2023-30097 json A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary w... 5.4 - MEDIUM 2023-05-04 2023-05-11
CVE-2023-30096 json A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary w... 5.4 - MEDIUM 2023-05-04 2023-05-11
CVE-2023-30095 json A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary w... 5.4 - MEDIUM 2023-05-04 2023-05-11
CVE-2023-30094 json A stored cross-site scripting (XSS) vulnerability in TotalJS Flow v10 allows attackers to execute arbitrary web scripts or HT... 5.4 - MEDIUM 2023-05-04 2023-05-11
CVE-2023-27070 json A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrar... 5.4 - MEDIUM 2023-03-14 2023-03-21
CVE-2023-27069 json A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrar... 5.4 - MEDIUM 2023-03-14 2023-03-22
CVE-2022-44019 json In Total.js 4 before 0e5ace7, /api/common/ping can achieve remote command execution via shell metacharacters in the host para... 8.8 - HIGH 2022-10-30 2023-08-08
CVE-2022-41392 json A cross-site scripting (XSS) vulnerability in TotalJS commit 8c2c8909 allows attackers to execute arbitrary web scripts or HT... 5.4 - MEDIUM 2022-10-07 2022-11-04
CVE-2022-30013 json A stored cross-site scripting (XSS) vulnerability in the upload function of totaljs CMS 3.4.5 allows attackers to execute arb... 5.4 - MEDIUM 2022-05-16 2022-05-24
CVE-2022-26565 json A cross-site scripting (XSS) vulnerability in Totaljs all versions before commit 95f54a5commit, allows attackers to execute a... 4.8 - MEDIUM 2022-04-01 2022-05-10
CVE-2021-32831 json Total.js framework (npm package total.js) is a framework for Node.js platfrom written in pure JavaScript similar to PHP's Lar... 7.2 - HIGH 2021-08-30 2021-09-07
CVE-2021-23390 json The package total4 before 0.0.43 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions. 9.8 - CRITICAL 2021-07-12 2021-07-14
CVE-2021-23389 json The package total.js before 3.4.9 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions. 9.8 - CRITICAL 2021-07-12 2021-07-14
CVE-2021-23344 json The package total.js before 3.4.8 are vulnerable to Remote Code Execution (RCE) via set. 9.8 - CRITICAL 2021-03-04 2021-03-05
CVE-2020-28495 json This affects the package total.js before 3.4.7. The set function can be used to set a value into the object according to the ... 7.3 - HIGH 2021-02-02 2021-02-05
CVE-2020-28494 json This affects the package total.js before 3.4.7. The issue occurs in the image.pipe and image.stream functions. The type param... 8.6 - HIGH 2021-02-02 2021-07-21
CVE-2020-9381 json controllers/admin.js in Total.js CMS 13 allows remote attackers to execute arbitrary code via a POST to the /admin/api/widget... 7.5 - HIGH 2020-02-24 2022-07-12
CVE-2019-15955 json An issue was discovered in Total.js CMS 12.0.0. A low privilege user can perform a simple transformation of a cookie to obtai... 6.5 - MEDIUM 2019-09-05 2021-07-21

Known software with vulnerabilities from Totaljs

Type Vendor Product Version
ApplicationTotaljsTotal.js1.0.0
ApplicationTotaljsTotal.js Cms13.0.0

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report