A vulnerability has been found in Total.js CMS up to 19.9.0. This impacts an unknown function of the component Files Menu. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
References
| Link | Resource |
|---|---|
| https://vuldb.com/?ctiid.325962 | Permissions Required VDB Entry |
| https://vuldb.com/?id.325962 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.651427 | Third Party Advisory VDB Entry |
Configurations
History
16 Jan 2026, 17:01
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:totaljs:total.js:*:*:*:*:*:node.js:*:* | |
| First Time |
Totaljs
Totaljs total.js |
|
| References | () https://vuldb.com/?ctiid.325962 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.325962 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.651427 - Third Party Advisory, VDB Entry |
26 Sep 2025, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-09-26 15:16
Updated : 2026-01-16 17:01
NVD link : CVE-2025-11019
Mitre link : CVE-2025-11019
CVE.ORG link : CVE-2025-11019
JSON object : View
Products Affected
totaljs
- total.js
