A vulnerability, which was classified as problematic, has been found in Total.js CMS 1.0.0. Affected by this vulnerability is the function layouts_save of the file /admin/ of the component Layout Page. Performing a manipulation of the argument HTML results in cross site scripting. This vulnerability is cataloged as CVE-2025-10940. It is possible... Weiterlesen: CVE-2025-10940 | Total.js CMS 1.0.0 Layout Page /admin/ layouts_save …
Intelligence View
⚡ tsecurity.de Intelligence
CVE-2025-10940 | Total.js CMS 1.0.0 Layout Page /admin/ layouts_save HTML cross site scripting (EUVD-2025-31081 / CNNVD-202509-4006)
A vulnerability, which was classified as problematic, has been found in Total.js CMS 1.0.0. Affected by this vulnerability is the function layouts_save of the…
Cyber Threat Intelligence & Forensik
ATT&CK-Navigator · IoC-Radar · Exploit-Belege
Compliance, SLA & Vendor Adherence
Advisory-Prüfung · Score-Einordnung · Fristen
NVD Primärbewertung & CISA SSVCCVE-2025-10940
NVD: AnalyzedNVD 4.8 · MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
NVD-Datenstand: 30.09.2026, 23:10 UTC
Ausnutzung beobachtet: Public PoC Automatisierbar: Nein Technischer Impact: Teilweise
CISA-SSVC-Triage (vulnrichment)CVE-2025-10940
Exploitation: poc (PoC verfügbar)Automatable: no (Nicht automatisierbar)Technical Impact: partial (Teilweise)
Quelle: CISA-ADP vulnrichment · Stand 2025-09-25T13:19:52.861044Z · CISA Coordinator
Advisory Radar
In herstellerseitiger Prüfung