VendorsTotaljstotal.jsall versions
Vulnerabilities

Totaljs Total.js

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2021-23344
Remote Code Execution (RCE)
Published 2021-03-04 · Modified
9.8EPSS 0.049
CVE-2021-23389
Arbitrary Code Execution
Published 2021-07-12 · Modified
9.8EPSS 0.036
CVE-2022-44019
In Total.js 4 before 0e5ace7, /api/common/ping can achieve remote command execution via shell metacharacters in the host parameter.
Published 2022-10-29 · Modified
8.8EPSS 0.022
CVE-2024-48655
An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file.
Published 2024-10-25 · Analyzed
8.8EPSS 0.010
CVE-2020-28494
Command Injection
Published 2021-02-02 · Modified
8.6EPSS 0.017
CVE-2019-8903
index.js in Total.js Platform before 3.2.3 allows path traversal.
Published 2019-02-18 · Modified
7.5EPSS 0.721
CVE-2020-28495
Prototype Pollution
Published 2021-02-02 · Modified
7.5EPSS 0.036
CVE-2021-32831
Code injection in total.js
Published 2021-08-30 · Modified
7.5EPSS 0.015
CVE-2022-41392
A cross-site scripting (XSS) vulnerability in TotalJS commit 8c2c8909 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website name text field under Main Settings.
Published 2022-10-07 · Modified
5.4EPSS 0.007
CVE-2022-30013
A stored cross-site scripting (XSS) vulnerability in the upload function of totaljs CMS 3.4.5 allows attackers to execute arbitrary web scripts via a JavaScript embedded PDF file.
Published 2022-05-16 · Modified
5.4EPSS 0.006
CVE-2025-10940
Total.js CMS Layout admin layouts_save cross site scripting
Published 2025-09-25 · Analyzed
4.8EPSS 0.003
CVE-2025-11019
Total.js CMS Files Menu cross site scripting
Published 2025-09-26 · Analyzed
4.8EPSS 0.002