📦 Turms

by Turms Im

🔍 What is Turms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-66909

HIGH CVSS 7.5 Dec 19, 2025

This vulnerability allows unauthenticated attackers to cause denial of service by uploading specially crafted image files that trigger memory exhaustion when decompressed. The Turms AI-Serving module'...

CVE-2025-66906

MEDIUM CVSS 6.1 Dec 19, 2025

This CSRF vulnerability in Turms Admin API allows attackers to trick authenticated administrators into performing unintended actions, potentially granting attackers escalated privileges. It affects al...

CVE-2025-66908

MEDIUM CVSS 5.3 Dec 19, 2025

This vulnerability allows attackers to upload arbitrary files including executables, scripts, or web shells by bypassing file type validation in Turms AI-Serving's OCR functionality. The system only c...

CVE-2025-66910

MEDIUM CVSS 6.0 Dec 19, 2025

Turms Server versions v0.10.0-SNAPSHOT and earlier store administrator passwords in plaintext memory after successful login. Attackers with local system access can extract these passwords via memory a...

CVE-2025-66911

MEDIUM CVSS 6.5 Dec 19, 2025

This vulnerability in Turms IM Server allows any authenticated user to query the online status, device information, and login timestamps of arbitrary users without proper authorization checks. It affe...