Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Totaljs

First CVE: Feb 18, 2019Active for: 7 yearsTotal CVEs: 26
47.0
VTI Score
High

Totaljs is a lightweight web application framework and platform ecosystem centered around its core runtime, content management system, and integrated messaging and API-orchestration components. Despite serving a focused product portfolio, the vendor maintains prominence within its application-development niche and carries a vulnerability profile where critical-severity outcomes occur with meaningful frequency. The recurring weakness classes—cross-site scripting, code injection, path traversal, OS command injection, and missing authorization—reflect the input-handling and privilege-boundary demands of a web framework and integrated middleware stack, and these flaws recur across the framework itself and its bundled platform products. A moderate share of disclosed vulnerabilities acquire public exploit tooling, underscoring the value of timely patching across deployed instances. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
26
Total CVEs
More Total CVEs than 97% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Totaljs over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 18, 2019
7 years ago
Most Recent CVE
Sep 26, 2025
301 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-15954CRITICAL
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote Command Execution (RCE) on the remote server by creating a
Sep 5, 20199.988NOYES
CVE-2019-8903HIGH
index.js in Total.js Platform before 3.2.3 allows path traversal.
Feb 18, 20197.575NOYES
CVE-2021-23344CRITICAL
The package total.js before 3.4.8 are vulnerable to Remote Code Execution (RCE) via set.
Mar 4, 20219.833NONO
CVE-2022-44019HIGH
In Total.js 4 before 0e5ace7, /api/common/ping can achieve remote command execution via shell metacharacters in the host parameter.
Oct 30, 20228.829NONO
CVE-2021-23390CRITICAL
The package total4 before 0.0.43 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.
Jul 12, 20219.829NONO
CVE-2021-23389CRITICAL
The package total.js before 3.4.9 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.
Jul 12, 20219.829NONO
CVE-2019-15952HIGH
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the Pages privilege can conduct a path traversal attack (../) to include .html files that are outside the
Sep 5, 20198.829NONO
CVE-2019-15953HIGH
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with limited privileges can get access to a resource that they do not own by calling the associated API. The p
Sep 5, 20198.827NONO
CVE-2024-48655HIGH
An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file.
Oct 25, 20248.824NONO
CVE-2020-28495HIGH
This affects the package total.js before 3.4.7. The set function can be used to set a value into the object according to the path. However the keys of the path being set are not pr
Feb 2, 20217.324NONO
View all 26 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products26 CVEs
50%
35%
15%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network26 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low26 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None14 (53.8%)
Unknown0 (0.0%)
Required12 (46.2%)
Privileges Required
Low14 (53.8%)
High4 (15.4%)
None8 (30.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
7.7% of CVEs· 98th percentile
Nuclei
1 CVE
3.8% of CVEs· 95th percentile
ExploitDB
1 CVE
3.8% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Totaljs.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Totaljs — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Totaljs's Products

View all 4 CNAs →

Top CWEs