Ptc Vuforia Studio
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Ptc Vuforia Studio.
By the Year
In 2026 there have been 0 vulnerabilities in Ptc Vuforia Studio. Vuforia Studio did not have any published security vulnerabilities last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 0 | 0.00 |
| 2024 | 0 | 0.00 |
| 2023 | 6 | 6.85 |
It may take a day or so for new Vuforia Studio vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Ptc Vuforia Studio Security Vulnerabilities
Vuforia: resourceDirectory Path Manipulation in appConfig.json
CVE-2023-29502
4.3 - Medium
- June 07, 2023
Before importing a project into Vuforia, a user could modify the resourceDirectory attribute in the appConfig.json file to be a different path.
Directory traversal
Local Traffic Replay Enables Unauthorized Request Execution (CVE-2023-24476)
CVE-2023-24476
3.3 - Low
- June 07, 2023
An attacker with local access to the machine could record the traffic, which could allow them to resend requests without the server authenticating that the user or session are valid.
Vuforia Server Filename Param Allows Deletion of Arbitrary Files
CVE-2023-29152
8.1 - High
- June 07, 2023
By changing the filename parameter in the request, an attacker could delete any file with the permissions of the Vuforia server account.
PTC Vuforia Studio No-Token Auth Allows CSRF / Replay Attack
CVE-2023-31200
8 - High
- June 07, 2023
PTC Vuforia Studio does not require a token; this could allow an attacker with local access to perform a cross-site request forgery attack or a replay attack.
Session Riding
Vuforia Web App: Unencrypted Basic Auth Credentials Exposed (CVE-2023-29168)
CVE-2023-29168
7.5 - High
- June 07, 2023
The local Vuforia web application does not support HTTPS, and federated credentials are passed via basic authentication.
Insufficiently Protected Credentials
Moodle Arbitrary File Upload via Upload Resource (CVE-2023-27881)
CVE-2023-27881
9.9 - Critical
- June 07, 2023
A user could use the Upload Resource functionality to upload files to any location on the disk.
Unrestricted File Upload
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Ptc Vuforia Studio or by Ptc? Click the Watch button to subscribe.