Vulnerability index

Browse CVEs

23 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Total.js HIGH 8.8
CVE-2024-48655

An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file.

No fix yet
Fix from $1,950 2024-10-25
Flow MEDIUM 5.4
CVE-2023-30094

A stored cross-site scripting (XSS) vulnerability in TotalJS Flow v10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload…

No fix yet
Fix from $1,600 2023-05-04
Messenger MEDIUM 5.4
CVE-2023-30095

A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or HTML via a…

No fix yet
Fix from $1,600 2023-05-04
Messenger MEDIUM 5.4
CVE-2023-30096

A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or HTML via a…

No fix yet
Fix from $1,600 2023-05-04
Messenger MEDIUM 5.4
CVE-2023-30097

A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or HTML via a…

No fix yet
Fix from $1,600 2023-05-04
Openplatform MEDIUM 5.4
CVE-2023-27069

A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts or HTML vi…

No fix yet
Fix from $1,600 2023-03-14
Openplatform MEDIUM 5.4
CVE-2023-27070

A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts or HTML vi…

No fix yet
Fix from $1,600 2023-03-14
Total.js HIGH 8.8
CVE-2022-44019

In Total.js 4 before 0e5ace7, /api/common/ping can achieve remote command execution via shell metacharacters in the host parameter.

Fix: 2022-09-26+
Fix from $1,950 2022-10-30
Total.js MEDIUM 5.4
CVE-2022-41392

A cross-site scripting (XSS) vulnerability in TotalJS commit 8c2c8909 allows attackers to execute arbitrary web scripts or HTML via a crafted payload…

No fix yet
Fix from $1,600 2022-10-07
Total.js MEDIUM 5.4
CVE-2022-30013

A stored cross-site scripting (XSS) vulnerability in the upload function of totaljs CMS 3.4.5 allows attackers to execute arbitrary web scripts via a…

No fix yet
Fix from $1,600 2022-05-16
Total.js HIGH 7.2
CVE-2021-32831

Total.js framework (npm package total.js) is a framework for Node.js platfrom written in pure JavaScript similar to PHP's Laravel or Python's Django …

Fix: 3.4.9+
Fix from $1,950 2021-08-30
Total4 CRITICAL 9.8
CVE-2021-23390

The package total4 before 0.0.43 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.

Fix: 0.0.43+
Fix from $2,300 2021-07-12
Total.js CRITICAL 9.8
CVE-2021-23389

The package total.js before 3.4.9 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.

Fix: 3.4.9+
Fix from $2,300 2021-07-12
Total.js CRITICAL 9.8
CVE-2021-23344

The package total.js before 3.4.8 are vulnerable to Remote Code Execution (RCE) via set.

Fix: 3.4.8+
Fix from $2,300 2021-03-04
Total.js HIGH 8.6
CVE-2020-28494

This affects the package total.js before 3.4.7. The issue occurs in the image.pipe and image.stream functions. The type parameter is used to build th…

Fix: 3.4.7+
Fix from $1,950 2021-02-02
Total.js HIGH 7.3
CVE-2020-28495

This affects the package total.js before 3.4.7. The set function can be used to set a value into the object according to the path. However the keys o…

Fix: 3.4.7+
Fix from $1,950 2021-02-02
Total.js Cms HIGH 7.5
CVE-2020-9381

controllers/admin.js in Total.js CMS 13 allows remote attackers to execute arbitrary code via a POST to the /admin/api/widgets/ URI. This can be expl…

Patch available
Fix from $1,950 2020-02-24
Total.js Cms CRITICAL 9.9
CVE-2019-15954EPSS 79%

An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote Command Execution (RCE) on t…

No fix yet
Fix from $2,300 2019-09-05
Total.js Cms MEDIUM 6.5
CVE-2019-15955

An issue was discovered in Total.js CMS 12.0.0. A low privilege user can perform a simple transformation of a cookie to obtain the random values insi…

No fix yet
Fix from $1,600 2019-09-05
Total.js Cms HIGH 8.8
CVE-2019-15952EPSS 5%

An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the Pages privilege can conduct a path traversal attack (../) to include .…

No fix yet
Fix from $1,950 2019-09-05
Total.js Cms HIGH 8.8
CVE-2019-15953

An issue was discovered in Total.js CMS 12.0.0. An authenticated user with limited privileges can get access to a resource that they do not own by ca…

No fix yet
Fix from $1,950 2019-09-05
Total.js Cms MEDIUM 6.1
CVE-2019-10260

Total.js CMS 12.0.0 has XSS related to themes/admin/views/index.html (item.message) and themes/admin/public/ui.js (column.format).

Patch available
Fix from $1,600 2019-03-28
Total.js HIGH 7.5
CVE-2019-8903EPSS 72%

index.js in Total.js Platform before 3.2.3 allows path traversal.

Fix: 3.2.3+
Fix from $1,950 2019-02-18