CVE-2023-45795: Pilz Pasvisu
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
A cross-site scripting vulnerability in the Builder Component of Pilz PASvisu before 1.14.1 allows a local unauthenticated attacker to inject malicious javascript and gain full control over the device.
Affected products
- Pilz Pasvisu: from 0.0.0, before 1.14.1 (fixed in 1.14.1)
- Pilz Pmi v8xx: from 0.0.0, up to and including 2.0.33992
Published 2026-06-22. Last modified 2026-09-26.