Totaljs is a lightweight web application framework and platform ecosystem centered around its core runtime, content management system, and integrated messaging and API-orchestration components. Despite serving a focused product portfolio, the vendor maintains prominence within its application-development niche and carries a vulnerability profile where critical-severity outcomes occur with meaningful frequency. The recurring weakness classes—cross-site scripting, code injection, path traversal, OS command injection, and missing authorization—reflect the input-handling and privilege-boundary demands of a web framework and integrated middleware stack, and these flaws recur across the framework itself and its bundled platform products. A moderate share of disclosed vulnerabilities acquire public exploit tooling, underscoring the value of timely patching across deployed instances. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Totaljs over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-15954CRITICAL An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote Command Execution (RCE) on the remote server by creating a | Sep 5, 2019 | 9.9 | 88 | NO | YES |
CVE-2019-8903HIGH index.js in Total.js Platform before 3.2.3 allows path traversal. | Feb 18, 2019 | 7.5 | 75 | NO | YES |
CVE-2021-23344CRITICAL The package total.js before 3.4.8 are vulnerable to Remote Code Execution (RCE) via set. | Mar 4, 2021 | 9.8 | 33 | NO | NO |
CVE-2022-44019HIGH In Total.js 4 before 0e5ace7, /api/common/ping can achieve remote command execution via shell metacharacters in the host parameter. | Oct 30, 2022 | 8.8 | 29 | NO | NO |
CVE-2021-23390CRITICAL The package total4 before 0.0.43 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions. | Jul 12, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-23389CRITICAL The package total.js before 3.4.9 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions. | Jul 12, 2021 | 9.8 | 29 | NO | NO |
CVE-2019-15952HIGH An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the Pages privilege can conduct a path traversal attack (../) to include .html files that are outside the | Sep 5, 2019 | 8.8 | 29 | NO | NO |
CVE-2019-15953HIGH An issue was discovered in Total.js CMS 12.0.0. An authenticated user with limited privileges can get access to a resource that they do not own by calling the associated API. The p | Sep 5, 2019 | 8.8 | 27 | NO | NO |
CVE-2024-48655HIGH An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file. | Oct 25, 2024 | 8.8 | 24 | NO | NO |
CVE-2020-28495HIGH This affects the package total.js before 3.4.7. The set function can be used to set a value into the object according to the path. However the keys of the path being set are not pr | Feb 2, 2021 | 7.3 | 24 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Totaljs.
Media articles that mention a CVE ID that affects a product developed by Totaljs — matched by CVE ID, not by vendor name.