Thm maintains a small, focused portfolio centered on web-based administrative and feedback platforms, including Pilos and its feedback system, that handle user data and service configuration. The vendor's vulnerability disclosures cluster around information-disclosure and input-handling weaknesses, including cleartext storage of sensitive data, cross-site request forgery, and improper input validation, reflecting the authentication and session-management demands of web applications. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Thm over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-47107HIGH PILOS is an open source front-end for BigBlueButton servers with a built-in load balancer. The password reset component deployed within PILOS uses the hostname supplied within the | Nov 8, 2023 | 8.8 | 24 | NO | NO |
CVE-2025-62523MEDIUM PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. PILOS before 4.8.0 includes a Cross-Origin Resource Sharing (CORS) misconfiguration in its mi | Oct 27, 2025 | 6.3 | 22 | NO | NO |
CVE-2025-62524MEDIUM PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. PILOS before 4.8.0 exposes the PHP version via the X-Powered-By header, enabling attackers to | Oct 27, 2025 | 5.3 | 20 | NO | NO |
CVE-2025-62781MEDIUM PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. Prior to 4.8.0, users with a local account can change their password while logged in. When do | Oct 27, 2025 | 5.0 | 19 | NO | NO |
CVE-2026-22800MEDIUM PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. Prior to 4.10.0, Cross-Site Request Forgery (CSRF) vulnerability exists in an administrative | Jan 12, 2026 | 4.5 | 18 | NO | NO |
CVE-2023-27485MEDIUM thmmniii/fbs-core is an open source feedback system for students. In versions prior to 1.5.3 when querying `subresults`, it is possible to query `subresults` from other users due t | Mar 7, 2023 | 4.3 | 18 | NO | NO |
CVE-2023-37468MEDIUM Feedbacksystem is a personalized feedback system for students using artificial intelligence. Passwords of users using LDAP login are stored in clear text in the database. The LDAP | Jul 13, 2023 | 5.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Thm.
Media articles that mention a CVE ID that affects a product developed by Thm — matched by CVE ID, not by vendor name.