Totvs is a Brazilian enterprise software vendor with a focused portfolio centered on business process and workflow applications such as Fluig, RM, and its Protheus framework, targeting mid-market and large organizations in Latin America. The durable signal in its vulnerability profile reflects application-layer weaknesses including cross-site scripting, authentication bypass, code injection, and path traversal, typical of web-facing business software with complex input handling and access control requirements. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Totvs over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-29134HIGH The TOTVS Fluig platform allows path traversal through the parameter "file = .. /" encoded in base64. This affects all versions Fluig Lake 1.7.0, Fluig 1.6.5 and Fluig 1.6.4 | Mar 5, 2021 | 8.6 | 32 | NO | NO |
CVE-2023-6275MEDIUM A vulnerability was found in TOTVS Fluig Platform 1.6.x/1.7.x/1.8.0/1.8.1. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /mobil | Nov 24, 2023 | 6.1 | 28 | NO | YES |
CVE-2024-55210CRITICAL An issue in TOTVS Framework (Linha Protheus) 12.1.2310 allows attackers to bypass multi-factor authentication (MFA) via a crafted websocket message. | Apr 9, 2025 | 9.8 | 26 | NO | NO |
CVE-2023-4710MEDIUM A vulnerability classified as problematic was found in TOTVS RM 12.1. Affected by this vulnerability is an unknown functionality of the component Portal. The manipulation of the ar | Sep 1, 2023 | 6.1 | 21 | NO | NO |
CVE-2023-4709MEDIUM A vulnerability classified as problematic has been found in TOTVS RM 12.1. Affected is an unknown function of the file Login.aspx of the component Portal. The manipulation of the a | Sep 1, 2023 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Totvs.
Media articles that mention a CVE ID that affects a product developed by Totvs — matched by CVE ID, not by vendor name.