Turms is an open-source instant-messaging server platform with a narrow product footprint but notable deployment prominence in cloud and enterprise messaging contexts. The observed vulnerability exposure is concentrated in the core Turms server product itself; current severity and exploitation details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Turms Im over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-66911MEDIUM Turms IM Server v0.10.0-SNAPSHOT and earlier contains a broken access control vulnerability in the user online status query functionality. The handleQueryUserOnlineStatusesRequest( | Dec 19, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-66909HIGH Turms AI-Serving module v0.10.0-SNAPSHOT and earlier contains an image decompression bomb denial of service vulnerability. The ExtendedOpenCVImage class in ai/djl/opencv/ExtendedOp | Dec 19, 2025 | 7.5 | 22 | NO | NO |
CVE-2025-66906MEDIUM Cross Site Request Forgery (CSRF) vulnerability in Turms Admin API thru v0.10.0-SNAPSHOT allows attackers to gain escalated privileges. | Dec 19, 2025 | 6.1 | 21 | NO | NO |
CVE-2025-66910MEDIUM Turms Server v0.10.0-SNAPSHOT and earlier contains a plaintext password storage vulnerability in the administrator authentication system. The BaseAdminService class caches administ | Dec 19, 2025 | 6.0 | 21 | NO | NO |
CVE-2025-66908MEDIUM Turms AI-Serving module v0.10.0-SNAPSHOT and earlier contains an improper file type validation vulnerability in the OCR image upload functionality. The OcrController in turms-ai-se | Dec 19, 2025 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Turms Im.
Media articles that mention a CVE ID that affects a product developed by Turms Im — matched by CVE ID, not by vendor name.