← Vulnerability feed

Vulnerability record · CVE-2020-9381 · published 24 February 2020

CVE-2020-9381: Totaljs total.js cms incorrect authorization vulnerability

Totaljs · Total.Js Cms

controllers/admin.js in Total.js CMS 13 allows remote attackers to execute arbitrary code via a POST to the /admin/api/widgets/ URI. This can be exploited in conjunction with CVE-2019-15954.

7.5 CVSS 3.1 High EPSS 2.1% · top 18.9% CWE-863 · Incorrect authorization
7.5CVSS 3.1 base score, v2 5.0
2.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

controllers/admin.js in Total.js CMS 13 allows remote attackers to execute arbitrary code via a POST to the /admin/api/widgets/ URI. This can be exploited in conjunction with CVE-2019-15954.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-9381 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2019-15954Total.js CMS widget tag sandbox escape leads to RCETotal.js CMS 12.0.0 evaluates widget tag content server side, and an authenticated user holding the widgets privilege can escape the sandbox object w…EPSS 79%analysed8.8CVE-2019-15952Totaljs total.js cms path traversal vulnerabilityAn issue was discovered in Total.js CMS 12.0.0. An authenticated user with the Pages privilege can conduct a path traversal attack (../) to include .…EPSS 5.1%8.8CVE-2019-15953Totaljs total.js cms missing authorization vulnerabilityAn issue was discovered in Total.js CMS 12.0.0. An authenticated user with limited privileges can get access to a resource that they do not own by ca…EPSS 1.5%6.5CVE-2019-15955Totaljs total.js cms broken cryptographic algorithm vulnerabilityAn issue was discovered in Total.js CMS 12.0.0. A low privilege user can perform a simple transformation of a cookie to obtain the random values insi…EPSS 0.87%6.1CVE-2019-10260Totaljs total.js cms cross-site scripting vulnerabilityTotal.js CMS 12.0.0 has XSS related to themes/admin/views/index.html (item.message) and themes/admin/public/ui.js (column.format).EPSS 0.91%9.1CVE-2026-71362Adobe commerce incorrect authorization vulnerabilityAdobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vul…KEVEPSS 88%8.8CVE-2026-42016JFrog Artifactory token scope bypass enables privilege escalationJFrog Artifactory (Self Hosted) before 7.133.11 validates a token's signature and issuer but not its scope, so a token can be used for actions beyond…KEVEPSS 8.6%analysed10.0CVE-2025-54253Adobe Experience Manager Forms misconfiguration allows pre-auth code executionAdobe Experience Manager Forms 6.5.23 and earlier contain a misconfiguration (CWE-863, incorrect authorization) that lets an attacker bypass security…KEVEPSS 88%analysed

Source: NIST National Vulnerability Database (record CVE-2020-9381), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.