Vulnerability index

Browse CVEs

23 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2024-48655 An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file. Total.js No fix yet Fix from $1,9502024-10-25 MEDIUM 5.4 CVE-2023-30094 A stored cross-site scripting (XSS) vulnerability in TotalJS Flow v10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload… Flow No fix yet Fix from $1,6002023-05-04 MEDIUM 5.4 CVE-2023-30095 A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or HTML via a… Messenger No fix yet Fix from $1,6002023-05-04 MEDIUM 5.4 CVE-2023-30096 A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or HTML via a… Messenger No fix yet Fix from $1,6002023-05-04 MEDIUM 5.4 CVE-2023-30097 A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or HTML via a… Messenger No fix yet Fix from $1,6002023-05-04 MEDIUM 5.4 CVE-2023-27069 A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts or HTML vi… Openplatform No fix yet Fix from $1,6002023-03-14 MEDIUM 5.4 CVE-2023-27070 A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts or HTML vi… Openplatform No fix yet Fix from $1,6002023-03-14 HIGH 8.8 CVE-2022-44019 In Total.js 4 before 0e5ace7, /api/common/ping can achieve remote command execution via shell metacharacters in the host parameter. Total.js 2022-09-26+ Fix from $1,9502022-10-30 MEDIUM 5.4 CVE-2022-41392 A cross-site scripting (XSS) vulnerability in TotalJS commit 8c2c8909 allows attackers to execute arbitrary web scripts or HTML via a crafted payload… Total.js No fix yet Fix from $1,6002022-10-07 MEDIUM 5.4 CVE-2022-30013 A stored cross-site scripting (XSS) vulnerability in the upload function of totaljs CMS 3.4.5 allows attackers to execute arbitrary web scripts via a… Total.js No fix yet Fix from $1,6002022-05-16 HIGH 7.2 CVE-2021-32831 Total.js framework (npm package total.js) is a framework for Node.js platfrom written in pure JavaScript similar to PHP's Laravel or Python's Django … Total.js 3.4.9+ Fix from $1,9502021-08-30 CRITICAL 9.8 CVE-2021-23390 The package total4 before 0.0.43 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions. Total4 0.0.43+ Fix from $2,3002021-07-12 CRITICAL 9.8 CVE-2021-23389 The package total.js before 3.4.9 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions. Total.js 3.4.9+ Fix from $2,3002021-07-12 CRITICAL 9.8 CVE-2021-23344 The package total.js before 3.4.8 are vulnerable to Remote Code Execution (RCE) via set. Total.js 3.4.8+ Fix from $2,3002021-03-04 HIGH 8.6 CVE-2020-28494 This affects the package total.js before 3.4.7. The issue occurs in the image.pipe and image.stream functions. The type parameter is used to build th… Total.js 3.4.7+ Fix from $1,9502021-02-02 HIGH 7.3 CVE-2020-28495 This affects the package total.js before 3.4.7. The set function can be used to set a value into the object according to the path. However the keys o… Total.js 3.4.7+ Fix from $1,9502021-02-02 HIGH 7.5 CVE-2020-9381 controllers/admin.js in Total.js CMS 13 allows remote attackers to execute arbitrary code via a POST to the /admin/api/widgets/ URI. This can be expl… Total.js Cms Patch available Fix from $1,9502020-02-24 CRITICAL 9.9 CVE-2019-15954EPSS 79% An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote Command Execution (RCE) on t… Total.js Cms No fix yet Fix from $2,3002019-09-05 MEDIUM 6.5 CVE-2019-15955 An issue was discovered in Total.js CMS 12.0.0. A low privilege user can perform a simple transformation of a cookie to obtain the random values insi… Total.js Cms No fix yet Fix from $1,6002019-09-05 HIGH 8.8 CVE-2019-15952EPSS 5% An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the Pages privilege can conduct a path traversal attack (../) to include .… Total.js Cms No fix yet Fix from $1,9502019-09-05 HIGH 8.8 CVE-2019-15953 An issue was discovered in Total.js CMS 12.0.0. An authenticated user with limited privileges can get access to a resource that they do not own by ca… Total.js Cms No fix yet Fix from $1,9502019-09-05 MEDIUM 6.1 CVE-2019-10260 Total.js CMS 12.0.0 has XSS related to themes/admin/views/index.html (item.message) and themes/admin/public/ui.js (column.format). Total.js Cms Patch available Fix from $1,6002019-03-28 HIGH 7.5 CVE-2019-8903EPSS 72% index.js in Total.js Platform before 3.2.3 allows path traversal. Total.js 3.2.3+ Fix from $1,9502019-02-18