Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
totaljs vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2022-44019
In Total.js 4 prior to 0e5ace7, /api/common/ping can achieve remote command execution via shell metacharacters in the host parameter.
Totaljs Total.js
9.8
CVSSv3
CVE-2021-23389
The package total.js prior to 3.4.9 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.
Totaljs Total.js
7.5
CVSSv3
CVE-2019-8903
index.js in Total.js Platform prior to 3.2.3 allows path traversal.
Totaljs Total.js
2 Github repositories
9.8
CVSSv3
CVE-2021-23344
The package total.js prior to 3.4.8 are vulnerable to Remote Code Execution (RCE) via set.
Totaljs Total.js
9.8
CVSSv3
CVE-2021-23390
The package total4 prior to 0.0.43 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.
Totaljs Total4
7.2
CVSSv3
CVE-2021-32831
Total.js framework (npm package total.js) is a framework for Node.js platfrom written in pure JavaScript similar to PHP's Laravel or Python's Django or ASP.NET MVC. In total.js framework before version 3.4.9, calling the utils.set function with user-controlled values le...
Totaljs Total.js
7.3
CVSSv3
CVE-2020-28495
This affects the package total.js prior to 3.4.7. The set function can be used to set a value into the object according to the path. However the keys of the path being set are not properly sanitized, leading to a prototype pollution vulnerability. The impact depends on the applic...
Totaljs Total.js
5.4
CVSSv3
CVE-2023-30095
A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the channel description field.
Totaljs Messenger -
5.4
CVSSv3
CVE-2023-30096
A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the user information field.
Totaljs Messenger -
5.4
CVSSv3
CVE-2023-30097
A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the private task field.
Totaljs Messenger -
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-26925
CVE-2023-41826
LFI
CVE-2022-22364
CVE-2024-2887
command injection
remote code execution
CVE-2024-34446
CVE-2022-48699
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »