Vulnerabilities > Totaljs > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-05-04 | CVE-2023-30094 | Cross-site Scripting vulnerability in Totaljs Flow 10.0 A stored cross-site scripting (XSS) vulnerability in TotalJS Flow v10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the platform name field in the settings module. | 5.4 |
2023-05-04 | CVE-2023-30095 | Cross-site Scripting vulnerability in Totaljs Messenger A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the channel description field. | 5.4 |
2023-05-04 | CVE-2023-30096 | Cross-site Scripting vulnerability in Totaljs Messenger A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the user information field. | 5.4 |
2023-05-04 | CVE-2023-30097 | Cross-site Scripting vulnerability in Totaljs Messenger A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the private task field. | 5.4 |
2023-03-14 | CVE-2023-27069 | Cross-site Scripting vulnerability in Totaljs Openplatform 20230216 A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the account name field. | 5.4 |
2023-03-14 | CVE-2023-27070 | Cross-site Scripting vulnerability in Totaljs Openplatform 20230216 A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the platform name field. | 5.4 |
2022-10-07 | CVE-2022-41392 | Cross-site Scripting vulnerability in Totaljs Total.Js 20220820 A cross-site scripting (XSS) vulnerability in TotalJS commit 8c2c8909 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website name text field under Main Settings. | 5.4 |
2022-05-16 | CVE-2022-30013 | Cross-site Scripting vulnerability in Totaljs Total.Js 3.4.5 A stored cross-site scripting (XSS) vulnerability in the upload function of totaljs CMS 3.4.5 allows attackers to execute arbitrary web scripts via a JavaScript embedded PDF file. | 5.4 |
2022-04-01 | CVE-2022-26565 | Cross-site Scripting vulnerability in Totaljs Content Management System A cross-site scripting (XSS) vulnerability in Totaljs all versions before commit 95f54a5commit, allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page Name text field when creating a new page. | 4.8 |
2019-09-05 | CVE-2019-15955 | Use of Insufficiently Random Values vulnerability in Totaljs Total.Js CMS 12.0.0 An issue was discovered in Total.js CMS 12.0.0. | 6.5 |