PT-2025-39646 · Unknown · Total.Js Cms

Mirandabr

·

Published

2025-09-26

·

Updated

2025-09-29

·

CVE-2025-11019

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Total.js CMS versions up to 19.9.0
Description A flaw exists in Total.js CMS that allows for cross site scripting through manipulation of an unknown function within the Files Menu component. This issue can be exploited remotely, and details about the exploit are publicly available.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-11019

Affected Products

Total.Js Cms