Vuforia Studio Ptc Vuforia Studio

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Ptc Vuforia Studio.

By the Year

In 2026 there have been 0 vulnerabilities in Ptc Vuforia Studio. Vuforia Studio did not have any published security vulnerabilities last year.

Year Vulnerabilities Average Score
2026 0 0.00
2025 0 0.00
2024 0 0.00
2023 6 6.85

It may take a day or so for new Vuforia Studio vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Ptc Vuforia Studio Security Vulnerabilities

Vuforia: resourceDirectory Path Manipulation in appConfig.json
CVE-2023-29502 4.3 - Medium - June 07, 2023

Before importing a project into Vuforia, a user could modify the resourceDirectory attribute in the appConfig.json file to be a different path.

Directory traversal

Local Traffic Replay Enables Unauthorized Request Execution (CVE-2023-24476)
CVE-2023-24476 3.3 - Low - June 07, 2023

An attacker with local access to the machine could record the traffic, which could allow them to resend requests without the server authenticating that the user or session are valid.

Vuforia Server Filename Param Allows Deletion of Arbitrary Files
CVE-2023-29152 8.1 - High - June 07, 2023

By changing the filename parameter in the request, an attacker could delete any file with the permissions of the Vuforia server account.

PTC Vuforia Studio No-Token Auth Allows CSRF / Replay Attack
CVE-2023-31200 8 - High - June 07, 2023

PTC Vuforia Studio does not require a token; this could allow an attacker with local access to perform a cross-site request forgery attack or a replay attack.

Session Riding

Vuforia Web App: Unencrypted Basic Auth Credentials Exposed (CVE-2023-29168)
CVE-2023-29168 7.5 - High - June 07, 2023

The local Vuforia web application does not support HTTPS, and federated credentials are passed via basic authentication.

Insufficiently Protected Credentials

Moodle Arbitrary File Upload via Upload Resource (CVE-2023-27881)
CVE-2023-27881 9.9 - Critical - June 07, 2023

A user could use the Upload Resource functionality to upload files to any location on the disk.

Unrestricted File Upload

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Ptc Vuforia Studio or by Ptc? Click the Watch button to subscribe.

Ptc
Vendor

subscribe