---
id: CVE-2025-11019
title: A vulnerability has been found in Total.js CMS up to 19.9.0
summary: >-
  A vulnerability has been found in Total.js CMS up to 19.9.0. This impacts an
  unknown function of the component Files Menu. The manipulation leads to cross
  site scripting. The attack can be initiated remotely. The exploit has been
  disclos…
severity: low
cvss: 2.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-79
  - CWE-94
  - CWE-79
vendor: totaljs
product: total.js
affected:
  - total.js < 19.9.0
patched:
  - total.js 19.9.0
published: '2025-09-26'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T10:10:00.193'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11019'
references:
  - url: 'https://vuldb.com/?ctiid.325962'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.325962'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.651427'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00242
epssPercentile: 0.14087
ingestedAt: '2026-10-09T12:53:27.631Z'
---

## Overview

A vulnerability has been found in Total.js CMS up to 19.9.0. This impacts an unknown function of the component Files Menu. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

## Affected

- `total.js < 19.9.0`

## Remediation

Upgrade past the affected range:

- `total.js 19.9.0`
