VYPR

PI Web API

by Aveva

CVEs (2)

  • CVE-2024-3468HigJun 12, 2024
    risk 0.55cvss epss 0.00

    There is a vulnerability in AVEVA PI Web API that could allow malicious code to execute on the PI Web API environment under the privileges of an interactive user that was socially engineered to use API XML import functionality with content supplied by an attacker.

  • CVE-2025-2745MedJun 12, 2025
    risk 0.42cvss 6.5epss 0.00

    A cross-site scripting vulnerability exists in AVEVA PI Web API version 2023 SP1 and prior that, if exploited, could allow an authenticated attacker (with privileges to create/update annotations or upload media files) to persist arbitrary JavaScript code that will be…