VYPR
","additionalType":"https://schema.org/SoftwareApplication","sameAs":["https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15954"]},"keywords":"CVE-2019-15954, Critical, CWE-77, CWE-862, Totaljs Total.js CMS, Total.js CMS","mentions":[{"@type":"SoftwareApplication","name":"Total.js CMS","applicationCategory":"SecurityApplication","publisher":{"@type":"Organization","name":"Totaljs"}},{"@type":"SoftwareApplication","name":"CMS","applicationCategory":"SecurityApplication","publisher":{"@type":"Organization","name":"Total.js"}}],"isAccessibleForFree":true},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://portal.vyprsec.ai/"},{"@type":"ListItem","position":2,"name":"CVEs","item":"https://portal.vyprsec.ai/cves"},{"@type":"ListItem","position":3,"name":"CVE-2019-15954","item":"https://portal.vyprsec.ai/cves/CVE-2019-15954"}]}]}
Critical severity9.9NVD Advisory· Published Sep 5, 2019· Updated Jun 17, 2026

CVE-2019-15954

CVE-2019-15954

Description

An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote Command Execution (RCE) on the remote server by creating a malicious widget with a special tag containing JavaScript code that will be evaluated server side. In the process of evaluating the tag by the back-end, it is possible to escape the sandbox object by using the following payload:

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.