Cross-Site Scripting Vulnerability in Total.js CMS by Total.js
CVE-2025-11019
4.8MEDIUM
What is CVE-2025-11019?
A cross-site scripting vulnerability has been identified in Total.js CMS up to version 19.9.0, specifically within the Files Menu component. This issue allows attackers to execute malicious scripts in the context of the user's browser, leading to potential data theft or manipulation. The vulnerability can be exploited remotely, making it crucial for users of affected versions to apply security measures swiftly to mitigate risks associated with this exploit.
Affected Version(s)
CMS 19.0
CMS 19.1
CMS 19.2