{"id":"CVE-2019-10260","details":"Total.js CMS 12.0.0 has XSS related to themes/admin/views/index.html (item.message) and themes/admin/public/ui.js (column.format).","aliases":["GHSA-72p5-2r6g-fm6v"],"modified":"2026-09-06T11:30:49.143812940Z","published":"2019-03-28T17:29:00.567Z","database_specific":{"unresolved_ranges":[{"vendor_product":"totaljs:total.js_cms","cpes":["cpe:2.3:a:totaljs:total.js_cms:12.0.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"12.0.0"},{"last_affected":"12.0.0"}],"source":"CPE_STRING"}]},"references":[{"type":"FIX","url":"https://github.com/totaljs/cms/commit/75205f93009db3cf8c0b0f4f1fc8ab82d70da8ad"},{"type":"FIX","url":"https://github.com/totaljs/cms/commit/8b9d7dada998c08d172481d9f0fc0397c4b3c78d"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/totaljs/cms","events":[{"introduced":"0"},{"fixed":"75205f93009db3cf8c0b0f4f1fc8ab82d70da8ad"},{"fixed":"8b9d7dada998c08d172481d9f0fc0397c4b3c78d"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-10260.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}