Vulnerability index

Browse CVEs

13 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Total.js HIGH 8.8
CVE-2024-48655

An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file.

No fix yet
Fix from $1,950 2024-10-25
Flow MEDIUM 5.4
CVE-2023-30094

A stored cross-site scripting (XSS) vulnerability in TotalJS Flow v10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload…

No fix yet
Fix from $1,600 2023-05-04
Messenger MEDIUM 5.4
CVE-2023-30095

A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or HTML via a…

No fix yet
Fix from $1,600 2023-05-04
Messenger MEDIUM 5.4
CVE-2023-30096

A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or HTML via a…

No fix yet
Fix from $1,600 2023-05-04
Messenger MEDIUM 5.4
CVE-2023-30097

A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or HTML via a…

No fix yet
Fix from $1,600 2023-05-04
Openplatform MEDIUM 5.4
CVE-2023-27069

A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts or HTML vi…

No fix yet
Fix from $1,600 2023-03-14
Openplatform MEDIUM 5.4
CVE-2023-27070

A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts or HTML vi…

No fix yet
Fix from $1,600 2023-03-14
Total.js MEDIUM 5.4
CVE-2022-41392

A cross-site scripting (XSS) vulnerability in TotalJS commit 8c2c8909 allows attackers to execute arbitrary web scripts or HTML via a crafted payload…

No fix yet
Fix from $1,600 2022-10-07
Total.js MEDIUM 5.4
CVE-2022-30013

A stored cross-site scripting (XSS) vulnerability in the upload function of totaljs CMS 3.4.5 allows attackers to execute arbitrary web scripts via a…

No fix yet
Fix from $1,600 2022-05-16
Total.js Cms CRITICAL 9.9
CVE-2019-15954EPSS 79%

An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote Command Execution (RCE) on t…

No fix yet
Fix from $2,300 2019-09-05
Total.js Cms MEDIUM 6.5
CVE-2019-15955

An issue was discovered in Total.js CMS 12.0.0. A low privilege user can perform a simple transformation of a cookie to obtain the random values insi…

No fix yet
Fix from $1,600 2019-09-05
Total.js Cms HIGH 8.8
CVE-2019-15952EPSS 5%

An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the Pages privilege can conduct a path traversal attack (../) to include .…

No fix yet
Fix from $1,950 2019-09-05
Total.js Cms HIGH 8.8
CVE-2019-15953

An issue was discovered in Total.js CMS 12.0.0. An authenticated user with limited privileges can get access to a resource that they do not own by ca…

No fix yet
Fix from $1,950 2019-09-05