{"id":"CVE-2019-10260","aliases":["GHSA-72p5-2r6g-fm6v"],"url":"https://o3.security/vulnerability/CVE-2019-10260","summary":"Moderate severity vulnerability that affects total.js","details":"Total.js CMS 12.0.0 has XSS related to themes/admin/views/index.html (item.message) and themes/admin/public/ui.js (column.format).","published":"2019-03-28T17:29:00.567Z","modified":"2026-08-01T11:30:29.035169947Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"total.js","fixedVersion":"3.3.0-13"}],"fix":{"url":"https://github.com/totaljs/cms/commit/75205f93009db3cf8c0b0f4f1fc8ab82d70da8ad","label":"totaljs/cms@75205f9"},"references":[{"type":"FIX","url":"https://github.com/totaljs/cms/commit/75205f93009db3cf8c0b0f4f1fc8ab82d70da8ad"},{"type":"FIX","url":"https://github.com/totaljs/cms/commit/8b9d7dada998c08d172481d9f0fc0397c4b3c78d"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-01T11:30:29.035169947Z"}}