CVE-2020-12021: Osisoft Pi Web API

Critical severity, CVSS 9.0. EPSS: 1.6% chance of exploitation in the next 30 days.

In OSIsoft PI Web API 2019 Patch 1 (1.12.0.6346) and all previous versions, the affected product is vulnerable to a cross-site scripting attack, which may allow an attacker to remotely execute arbitrary code.

Affected products

  • Osisoft Pi Web API: up to and including 2019; version 2019 only

Published 2020-06-23. Last modified 2026-06-17.