THM
THM Pilos: vulnerabilities and CVEs
THM Pilos has 6 published vulnerabilities, 5 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs6
Last 12 months5
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-71555 | Medium (4.1) | 0.29% | — | Aug 6, 2026 | PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. From 2.1.0 until 4.14.1, PILOS does not send a Cross-Origin-Opener-Policy response header, so pages opened by PILOS via a link that… |
| CVE-2026-22800 | Medium (4.5) | 0.15% | — | Jan 12, 2026 | PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. Prior to 4.10.0, Cross-Site Request Forgery (CSRF) vulnerability exists in an administrative API endpoint responsible for… |
| CVE-2025-62781 | Medium (5) | 0.17% | — | Oct 27, 2025 | PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. Prior to 4.8.0, users with a local account can change their password while logged in. When doing so, all other active sessions are… |
| CVE-2025-62524 | Medium (5.3) | 0.26% | — | Oct 27, 2025 | PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. PILOS before 4.8.0 exposes the PHP version via the X-Powered-By header, enabling attackers to fingerprint the server and assess… |
| CVE-2025-62523 | Medium (6.3) | 0.20% | — | Oct 27, 2025 | PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. PILOS before 4.8.0 includes a Cross-Origin Resource Sharing (CORS) misconfiguration in its middleware: it reflects the Origin… |
| CVE-2023-47107 | High (8.8) | 0.60% | — | Nov 8, 2023 | PILOS is an open source front-end for BigBlueButton servers with a built-in load balancer. The password reset component deployed within PILOS uses the hostname supplied within the request host header when building a… |