📦 Total.js

by Totaljs

🔍 What is Total.js?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-23389

CRITICAL CVSS 9.8 Jul 12, 2021

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of total.js framework. Attackers can exploit the U.set() and U.get() utility functions to in...

CVE-2021-23344

CRITICAL CVSS 9.8 Mar 4, 2021

This vulnerability in total.js framework allows remote attackers to execute arbitrary code on affected systems by exploiting improper input validation in the 'set' function. It affects all application...

CVE-2024-48655

HIGH CVSS 8.8 Oct 25, 2024

CVE-2024-48655 is a server-side JavaScript code injection vulnerability in Total.js CMS v1.0 that allows remote attackers to execute arbitrary code via the func.js file. This enables complete system c...

CVE-2021-32831

HIGH CVSS 7.5 Aug 30, 2021

CVE-2021-32831 is a code injection vulnerability in the Total.js framework for Node.js. When the utils.set function is called with user-controlled values, attackers can execute arbitrary code on affec...

CVE-2020-28494

HIGH CVSS 8.6 Feb 2, 2021

This vulnerability allows remote command injection in total.js framework versions before 3.4.7. Attackers can execute arbitrary commands on the server by exploiting insufficient input sanitization in ...