Vulnerabilities > Totaljs

DATE CVE VULNERABILITY TITLE RISK
2023-05-04 CVE-2023-30094 Cross-site Scripting vulnerability in Totaljs Flow 10.0
A stored cross-site scripting (XSS) vulnerability in TotalJS Flow v10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the platform name field in the settings module.
network
low complexity
totaljs CWE-79
5.4
2023-05-04 CVE-2023-30095 Cross-site Scripting vulnerability in Totaljs Messenger
A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the channel description field.
network
low complexity
totaljs CWE-79
5.4
2023-05-04 CVE-2023-30096 Cross-site Scripting vulnerability in Totaljs Messenger
A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the user information field.
network
low complexity
totaljs CWE-79
5.4
2023-05-04 CVE-2023-30097 Cross-site Scripting vulnerability in Totaljs Messenger
A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the private task field.
network
low complexity
totaljs CWE-79
5.4
2023-03-14 CVE-2023-27069 Cross-site Scripting vulnerability in Totaljs Openplatform 20230216
A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the account name field.
network
low complexity
totaljs CWE-79
5.4
2023-03-14 CVE-2023-27070 Cross-site Scripting vulnerability in Totaljs Openplatform 20230216
A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the platform name field.
network
low complexity
totaljs CWE-79
5.4
2022-10-30 CVE-2022-44019 OS Command Injection vulnerability in Totaljs Total.Js
In Total.js 4 before 0e5ace7, /api/common/ping can achieve remote command execution via shell metacharacters in the host parameter.
network
low complexity
totaljs CWE-78
8.8
2022-10-07 CVE-2022-41392 Cross-site Scripting vulnerability in Totaljs Total.Js 20220820
A cross-site scripting (XSS) vulnerability in TotalJS commit 8c2c8909 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website name text field under Main Settings.
network
low complexity
totaljs CWE-79
5.4
2022-05-16 CVE-2022-30013 Cross-site Scripting vulnerability in Totaljs Total.Js 3.4.5
A stored cross-site scripting (XSS) vulnerability in the upload function of totaljs CMS 3.4.5 allows attackers to execute arbitrary web scripts via a JavaScript embedded PDF file.
network
totaljs CWE-79
3.5
2022-04-01 CVE-2022-26565 Cross-site Scripting vulnerability in Totaljs Content Management System
A cross-site scripting (XSS) vulnerability in Totaljs all versions before commit 95f54a5commit, allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page Name text field when creating a new page.
network
totaljs CWE-79
3.5