Total.Js

Vendor:

First CVE: Feb 18, 2019 · Active for 7 years

12
Total CVEs
More Total CVEs than 90% of tracked products
2.4
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Total.Js over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 18, 2019
7 years ago
Most Recent CVE
Sep 26, 2025
302 days ago

CVE Severity & Scoring

Total.Js12 CVEs
All CVEs352,708 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (66.7%)
Unknown0 (0.0%)
Required4 (33.3%)
Privileges Required
Low4 (33.3%)
High3 (25.0%)
None5 (41.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
index.js in Total.js Platform before 3.2.3 allows path traversal.
Feb 18, 20197.575NOYES
The package total.js before 3.4.8 are vulnerable to Remote Code Execution (RCE) via set.
Mar 4, 20219.833NONO
In Total.js 4 before 0e5ace7, /api/common/ping can achieve remote command execution via shell metacharacters in the host parameter.
Oct 30, 20228.829NONO
The package total.js before 3.4.9 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.
Jul 12, 20219.829NONO
An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file.
Oct 25, 20248.824NONO
This affects the package total.js before 3.4.7. The set function can be used to set a value into the object according to the path. However the keys of the path being set are not pr
Feb 2, 20217.324NONO
Total.js framework (npm package total.js) is a framework for Node.js platfrom written in pure JavaScript similar to PHP's Laravel or Python's Django or ASP.NET MVC. In total.js fra
Aug 30, 20217.223NONO
This affects the package total.js before 3.4.7. The issue occurs in the image.pipe and image.stream functions. The type parameter is used to build the command that is then executed
Feb 2, 20218.622NONO
A vulnerability was found in Total.js CMS 1.0.0. Affected by this vulnerability is the function layouts_save of the file /admin/ of the component Layout Page. Performing manipulati
Sep 25, 20254.820NONO
A cross-site scripting (XSS) vulnerability in TotalJS commit 8c2c8909 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website name
Oct 7, 20225.420NONO

Exploit Exposure

Signals from CVEs in this product scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
8.3% of CVEs· 97th percentile
Nuclei
1 CVE
8.3% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (12 CVEs).

Media Mentions

Signals from CVEs in this product scope (12 CVEs).

Top CNAs Publishing CVEs For Total.Js

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.4.515.40.6%00
2022-08-2015.40.7%00
1.0.026.80.6%00