Total.Js
Vendor:
First CVE: Feb 18, 2019 · Active for 7 years
12
Total CVEs
More Total CVEs than 90% of tracked products
2.4
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Total.Js over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 18, 2019
7 years ago
Most Recent CVE
Sep 26, 2025
302 days ago
CVE Severity & Scoring
Total.Js12 CVEs
33%
50%
17%
All CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (66.7%)
Unknown0 (0.0%)
Required4 (33.3%)
Privileges Required
Low4 (33.3%)
High3 (25.0%)
None5 (41.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-8903HIGH index.js in Total.js Platform before 3.2.3 allows path traversal. | Feb 18, 2019 | 7.5 | 75 | NO | YES |
CVE-2021-23344CRITICAL The package total.js before 3.4.8 are vulnerable to Remote Code Execution (RCE) via set. | Mar 4, 2021 | 9.8 | 33 | NO | NO |
CVE-2022-44019HIGH In Total.js 4 before 0e5ace7, /api/common/ping can achieve remote command execution via shell metacharacters in the host parameter. | Oct 30, 2022 | 8.8 | 29 | NO | NO |
CVE-2021-23389CRITICAL The package total.js before 3.4.9 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions. | Jul 12, 2021 | 9.8 | 29 | NO | NO |
CVE-2024-48655HIGH An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file. | Oct 25, 2024 | 8.8 | 24 | NO | NO |
CVE-2020-28495HIGH This affects the package total.js before 3.4.7. The set function can be used to set a value into the object according to the path. However the keys of the path being set are not pr | Feb 2, 2021 | 7.3 | 24 | NO | NO |
CVE-2021-32831HIGH Total.js framework (npm package total.js) is a framework for Node.js platfrom written in pure JavaScript similar to PHP's Laravel or Python's Django or ASP.NET MVC. In total.js fra | Aug 30, 2021 | 7.2 | 23 | NO | NO |
CVE-2020-28494HIGH This affects the package total.js before 3.4.7. The issue occurs in the image.pipe and image.stream functions. The type parameter is used to build the command that is then executed | Feb 2, 2021 | 8.6 | 22 | NO | NO |
CVE-2025-10940MEDIUM A vulnerability was found in Total.js CMS 1.0.0. Affected by this vulnerability is the function layouts_save of the file /admin/ of the component Layout Page. Performing manipulati | Sep 25, 2025 | 4.8 | 20 | NO | NO |
CVE-2022-41392MEDIUM A cross-site scripting (XSS) vulnerability in TotalJS commit 8c2c8909 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website name | Oct 7, 2022 | 5.4 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
8.3% of CVEs· 97th percentile
Nuclei
1 CVE
8.3% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Total.Js
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.4.5 | 1 | 5.4 | 0.6% | 0 | 0 |
| 2022-08-20 | 1 | 5.4 | 0.7% | 0 | 0 |
| 1.0.0 | 2 | 6.8 | 0.6% | 0 | 0 |