Back to Database
Status published
High
CVE-2023-45795
Pilz: XSS vulnerability in Pilz PASvisu and PMI v8xx
Vulnerability Description
A cross-site scripting vulnerability in the Builder Component of Pilz PASvisu before 1.14.1 allows a local unauthenticated attacker to inject malicious javascript and gain full control over the device.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-45795
Credits & Attribution
No credits recorded in the NVD database.
More from Pilz
View All →CVE-2025-41656
Pilz: Missing Authentication in Node-RED integration
Critical
10
CVE-2025-41648
Pilz: Authentication Bypass in IndustrialPI Webstatus
Critical
9.8
CVE-2023-45796
XSS vulnerability in Pilz PASvisu and PMI v8xx
High
8.1
CVE-2018-19009
Pilz PNOZmulti Configurator prior to version 10.9 allows an authenticated...
High
7.8
Affected Vendor
Pilz
View all reports →Affected Software
PMI v8xx, PASvisu
Vulnerable Versions:
0.0.0
Timeline
Official Publish:
June 22nd, 2026
Last Modified:
June 22nd, 2026
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H