Vulnerability index

Browse CVEs

13 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2024-48655 An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file. Total.js No fix yet Fix from $1,9502024-10-25 MEDIUM 5.4 CVE-2023-30094 A stored cross-site scripting (XSS) vulnerability in TotalJS Flow v10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload… Flow No fix yet Fix from $1,6002023-05-04 MEDIUM 5.4 CVE-2023-30095 A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or HTML via a… Messenger No fix yet Fix from $1,6002023-05-04 MEDIUM 5.4 CVE-2023-30096 A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or HTML via a… Messenger No fix yet Fix from $1,6002023-05-04 MEDIUM 5.4 CVE-2023-30097 A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or HTML via a… Messenger No fix yet Fix from $1,6002023-05-04 MEDIUM 5.4 CVE-2023-27069 A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts or HTML vi… Openplatform No fix yet Fix from $1,6002023-03-14 MEDIUM 5.4 CVE-2023-27070 A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts or HTML vi… Openplatform No fix yet Fix from $1,6002023-03-14 MEDIUM 5.4 CVE-2022-41392 A cross-site scripting (XSS) vulnerability in TotalJS commit 8c2c8909 allows attackers to execute arbitrary web scripts or HTML via a crafted payload… Total.js No fix yet Fix from $1,6002022-10-07 MEDIUM 5.4 CVE-2022-30013 A stored cross-site scripting (XSS) vulnerability in the upload function of totaljs CMS 3.4.5 allows attackers to execute arbitrary web scripts via a… Total.js No fix yet Fix from $1,6002022-05-16 CRITICAL 9.9 CVE-2019-15954EPSS 79% An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote Command Execution (RCE) on t… Total.js Cms No fix yet Fix from $2,3002019-09-05 MEDIUM 6.5 CVE-2019-15955 An issue was discovered in Total.js CMS 12.0.0. A low privilege user can perform a simple transformation of a cookie to obtain the random values insi… Total.js Cms No fix yet Fix from $1,6002019-09-05 HIGH 8.8 CVE-2019-15952EPSS 5% An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the Pages privilege can conduct a path traversal attack (../) to include .… Total.js Cms No fix yet Fix from $1,9502019-09-05 HIGH 8.8 CVE-2019-15953 An issue was discovered in Total.js CMS 12.0.0. An authenticated user with limited privileges can get access to a resource that they do not own by ca… Total.js Cms No fix yet Fix from $1,9502019-09-05