Vulnerabilities > Totaljs > Total JS
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-10-30 | CVE-2022-44019 | OS Command Injection vulnerability in Totaljs Total.Js In Total.js 4 before 0e5ace7, /api/common/ping can achieve remote command execution via shell metacharacters in the host parameter. | 8.8 |
2022-10-07 | CVE-2022-41392 | Cross-site Scripting vulnerability in Totaljs Total.Js 20220820 A cross-site scripting (XSS) vulnerability in TotalJS commit 8c2c8909 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website name text field under Main Settings. | 5.4 |
2022-05-16 | CVE-2022-30013 | Cross-site Scripting vulnerability in Totaljs Total.Js 3.4.5 A stored cross-site scripting (XSS) vulnerability in the upload function of totaljs CMS 3.4.5 allows attackers to execute arbitrary web scripts via a JavaScript embedded PDF file. | 5.4 |
2021-08-30 | CVE-2021-32831 | Unspecified vulnerability in Totaljs Total.Js Total.js framework (npm package total.js) is a framework for Node.js platfrom written in pure JavaScript similar to PHP's Laravel or Python's Django or ASP.NET MVC. | 7.2 |
2021-07-12 | CVE-2021-23389 | Code Injection vulnerability in Totaljs Total.Js The package total.js before 3.4.9 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions. | 9.8 |
2021-03-04 | CVE-2021-23344 | Code Injection vulnerability in Totaljs Total.Js The package total.js before 3.4.8 are vulnerable to Remote Code Execution (RCE) via set. | 9.8 |
2019-02-18 | CVE-2019-8903 | Path Traversal vulnerability in Totaljs Total.Js index.js in Total.js Platform before 3.2.3 allows path traversal. | 7.5 |