A vulnerability classified as problematic has been found in Total.js CMS up to 19.9.0. This impacts an unknown function of the component Files Menu. The manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2025-11019. The attack can be initiated remotely. Additionally, an exploit exists.