PT-2025-39359 · Unknown · Total.Js Cms

Edcarlos

·

Published

2025-09-25

·

Updated

2025-09-25

·

CVE-2025-10940

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Total.js CMS version 1.0.0
Description A cross site scripting issue exists in Total.js CMS version 1.0.0. The issue is located in the layouts save function within the /admin/ file of the Layout Page component. Manipulation of the HTML argument can trigger the issue. The attack can be initiated remotely. The exploit has been made public.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-10940

Affected Products

Total.Js Cms