CVE-2018-20092: PTC Thingworx Platform

High severity, CVSS 7.5. EPSS: 2.2% chance of exploitation in the next 30 days.

PTC ThingWorx Platform through 8.3.0 is vulnerable to a directory traversal attack on ZIP files via a POST request.

Affected products

  • PTC Thingworx Platform: from 7.0.0, up to and including 7.0.14; before 7.0.0 (fixed in 7.0.0); from 7.1.0, up to and including 7.1.18; from 7.2.0, up to and including 7.2.21; from 7.3.0, up to and including 7.3.18; from 7.4.0, up to and including 7.4.14; …

Published 2018-12-17. Last modified 2026-06-17.