Medium severity6.1OSV Advisory· Published Mar 28, 2019· Updated Jun 17, 2026
CVE-2019-10260
CVE-2019-10260
Description
Total.js CMS 12.0.0 has XSS related to themes/admin/views/index.html (item.message) and themes/admin/public/ui.js (column.format).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
total.jsnpm | < 3.3.0-13 | 3.3.0-13 |
Affected products
2Patches
Vulnerability mechanics
References
4- github.com/totaljs/cms/commit/75205f93009db3cf8c0b0f4f1fc8ab82d70da8adnvdPatchThird Party AdvisoryWEB
- github.com/totaljs/cms/commit/8b9d7dada998c08d172481d9f0fc0397c4b3c78dnvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-72p5-2r6g-fm6vghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-10260ghsaADVISORY
News mentions
0No linked articles in our index yet.