Show filters
23 Total Results
Displaying 1-10 of 23
Sort by:
Attacker Value
Moderate
CVE-2019-8903
Disclosure Date: February 18, 2019 (last updated October 06, 2023)
index.js in Total.js Platform before 3.2.3 allows path traversal.
1
Attacker Value
Unknown
CVE-2023-30097
Disclosure Date: May 04, 2023 (last updated October 08, 2023)
A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the private task field.
0
Attacker Value
Unknown
CVE-2023-30096
Disclosure Date: May 04, 2023 (last updated October 08, 2023)
A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the user information field.
0
Attacker Value
Unknown
CVE-2023-30095
Disclosure Date: May 04, 2023 (last updated October 08, 2023)
A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the channel description field.
0
Attacker Value
Unknown
CVE-2023-30094
Disclosure Date: May 04, 2023 (last updated October 08, 2023)
A stored cross-site scripting (XSS) vulnerability in TotalJS Flow v10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the platform name field in the settings module.
0
Attacker Value
Unknown
CVE-2023-27070
Disclosure Date: March 14, 2023 (last updated October 08, 2023)
A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the platform name field.
0
Attacker Value
Unknown
CVE-2023-27069
Disclosure Date: March 14, 2023 (last updated October 08, 2023)
A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the account name field.
0
Attacker Value
Unknown
CVE-2022-44019
Disclosure Date: October 30, 2022 (last updated December 22, 2024)
In Total.js 4 before 0e5ace7, /api/common/ping can achieve remote command execution via shell metacharacters in the host parameter.
0
Attacker Value
Unknown
CVE-2022-41392
Disclosure Date: October 07, 2022 (last updated December 22, 2024)
A cross-site scripting (XSS) vulnerability in TotalJS commit 8c2c8909 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website name text field under Main Settings.
0
Attacker Value
Unknown
CVE-2022-30013
Disclosure Date: May 16, 2022 (last updated October 07, 2023)
A stored cross-site scripting (XSS) vulnerability in the upload function of totaljs CMS 3.4.5 allows attackers to execute arbitrary web scripts via a JavaScript embedded PDF file.
0