thm records
7 published records for vendor thm.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 57.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-613 Insufficient Session Expiration1
- CWE-863 Incorrect Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2023-47107No exploit | PILOS account takeover through password reset poisoningthm · pilos · CWE-20 | High8.8 | — | 0.6% | Nov 8, 2023 |
25Monitor | CVE-2025-62523No exploit | PILOS Misconfigured the Access-Control-Allow-Origin Headerthm · pilos · CWE-942 | Medium6.3 | — | 0.2% | Oct 27, 2025 |
22Monitor | CVE-2023-37468No exploit | Storing unencrypted LDAP passwords in feedbacksystemthm · feedbacksystem · CWE-312 | Medium5.5 | — | 0.2% | Jul 13, 2023 |
21Monitor | CVE-2025-62524No exploit | PILOS Exposes PHP versionthm · pilos · CWE-200 | Medium5.3 | — | 0.3% | Oct 27, 2025 |
20Monitor | CVE-2025-62781No exploit | PILOS is missing session regeneration after password changethm · pilos · CWE-613 | Medium5.0 | — | 0.2% | Oct 27, 2025 |
18Monitor | CVE-2026-22800No exploit | PILOS affected by a CSRF via GET request allows unintentional termination of all active video conferencesthm · pilos · CWE-352 | Medium4.5 | — | 0.1% | Jan 12, 2026 |
17Monitor | CVE-2023-27485No exploit | Insufficient verification of authorisation when accessing subresults in thmmniii/fbs-corethm · feedbacksystem · CWE-863 | Medium4.3 | — | 0.5% | Mar 7, 2023 |
- CVE-2023-4710735Monitor
PILOS account takeover through password reset poisoning
HighCVSS 8.8No exploitEPSS 1%thm · pilosNov 8, 2023
- CVE-2025-6252325Monitor
PILOS Misconfigured the Access-Control-Allow-Origin Header
MediumCVSS 6.3No exploitEPSS 0%thm · pilosOct 27, 2025
- CVE-2023-3746822Monitor
Storing unencrypted LDAP passwords in feedbacksystem
MediumCVSS 5.5No exploitEPSS 0%thm · feedbacksystemJul 13, 2023
- CVE-2025-6252421Monitor
PILOS Exposes PHP version
MediumCVSS 5.3No exploitEPSS 0%thm · pilosOct 27, 2025
- CVE-2025-6278120Monitor
PILOS is missing session regeneration after password change
MediumCVSS 5.0No exploitEPSS 0%thm · pilosOct 27, 2025
- CVE-2026-2280018Monitor
PILOS affected by a CSRF via GET request allows unintentional termination of all active video conferences
MediumCVSS 4.5No exploitEPSS 0%thm · pilosJan 12, 2026
- CVE-2023-2748517Monitor
Insufficient verification of authorisation when accessing subresults in thmmniii/fbs-core
MediumCVSS 4.3No exploitEPSS 1%thm · feedbacksystemMar 7, 2023