CVE-2023-45795: Pilz Pasvisu

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

A cross-site scripting vulnerability in the Builder Component of Pilz PASvisu before 1.14.1 allows a local unauthenticated attacker to inject malicious javascript and gain full control over the device.

Affected products

  • Pilz Pasvisu: from 0.0.0, before 1.14.1 (fixed in 1.14.1)
  • Pilz Pmi v8xx: from 0.0.0, up to and including 2.0.33992

Published 2026-06-22. Last modified 2026-09-26.