Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Totvs

First CVE: Mar 5, 2021Active for: 5 yearsTotal CVEs: 5

Totvs is a Brazilian enterprise software vendor with a focused portfolio centered on business process and workflow applications such as Fluig, RM, and its Protheus framework, targeting mid-market and large organizations in Latin America. The durable signal in its vulnerability profile reflects application-layer weaknesses including cross-site scripting, authentication bypass, code injection, and path traversal, typical of web-facing business software with complex input handling and access control requirements. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
5
Total CVEs
More Total CVEs than 83% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Totvs over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 5, 2021
5 years ago
Most Recent CVE
Apr 9, 2025
474 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (5 CVEs).

5 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-29134HIGH
The TOTVS Fluig platform allows path traversal through the parameter "file = .. /" encoded in base64. This affects all versions Fluig Lake 1.7.0, Fluig 1.6.5 and Fluig 1.6.4
Mar 5, 20218.632NONO
CVE-2023-6275MEDIUM
A vulnerability was found in TOTVS Fluig Platform 1.6.x/1.7.x/1.8.0/1.8.1. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /mobil
Nov 24, 20236.128NOYES
CVE-2024-55210CRITICAL
An issue in TOTVS Framework (Linha Protheus) 12.1.2310 allows attackers to bypass multi-factor authentication (MFA) via a crafted websocket message.
Apr 9, 20259.826NONO
CVE-2023-4710MEDIUM
A vulnerability classified as problematic was found in TOTVS RM 12.1. Affected by this vulnerability is an unknown functionality of the component Portal. The manipulation of the ar
Sep 1, 20236.121NONO
CVE-2023-4709MEDIUM
A vulnerability classified as problematic has been found in TOTVS RM 12.1. Affected is an unknown function of the file Login.aspx of the component Portal. The manipulation of the a
Sep 1, 20236.120NONO
View all 5 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products5 CVEs
60%
20%
20%
Severity distribution among all CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network5 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (40.0%)
Unknown0 (0.0%)
Required3 (60.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None5 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (5 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
20.0% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Totvs.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Totvs — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Totvs's Products

View all 2 CNAs →

Top CWEs