Vulnerabilities
51 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-1563 +1 in the same advisory: …1562 | Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role. NVD description · AI analysis pending | 4.8 group max | <1% |
| — | ||
| CVE-2026-1564 +1 in the same advisory: …1711 | Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface component. Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface component. Requires a high privileged user with a developer role. NVD description · AI analysis pending | 5.1 group max | <1% |
| — | ||
| CVE-2025-62184 | Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to Confidentiality is low and Integrity is none. NVD description · AI analysis pending | 4.8 | <1% |
| — | ||
| CVE-2025-9559 | Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user interface component that can only be used to Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user interface component that can only be used to read data. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2025-8681 | Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component. Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component. Requires a high privileged user with a developer role. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2025-2161 +1 in the same advisory: …2160 | Pega Platform versions 7.2.1 to Infinity 24.2.1 are affected by an XSS issue with Mashup Pega Platform versions 7.2.1 to Infinity 24.2.1 are affected by an XSS issue with Mashup NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2024-12211 | Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile. Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2024-10716 | Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search. Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search. NVD description · AI analysis pending | 4.8 | <1% |
| — | ||
| CVE-2024-10094 | Pega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of Code Pega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of Code NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2024-6702 | Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage. Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage. NVD description · AI analysis pending | 4.8 | <1% |
| — | ||
| CVE-2023-50168 | Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation. Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation. NVD description · AI analysis pending | 7.7 | <1% |
| — | ||
| CVE-2023-50167 | Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content. Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2023-50165 +1 in the same advisory: …50166 | Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents. Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents. NVD description · AI analysis pending | 8.6 group max | <1% |
| — | ||
| CVE-2023-32089 | Pega Platform versions 8.1 to 8.8.2 are affected by an XSS issue with Pin description Pega Platform versions 8.1 to 8.8.2 are affected by an XSS issue with Pin description NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2023-4843 | Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Business Director, however this field can only Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Business Director, however this field can only be modified by an authenticated administrative user. NVD description · AI analysis pending | 4.8 | <1% |
| — | ||
| CVE-2023-32090 | Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2023-28094 | Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default credentials. Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default credentials. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2023-26465 | Pega Platform versions 7.2 to 8.8.1 are affected by an XSS issue. Pega Platform versions 7.2 to 8.8.1 are affected by an XSS issue. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2023-26466 | A user with non-Admin access can change a configuration file on the client to modify the Server URL. A user with non-Admin access can change a configuration file on the client to modify the Server URL. NVD description · AI analysis pending | 7.8 group max | <1% |
| — | ||
| CVE-2022-35654 | Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter. Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter. NVD description · AI analysis pending | 6.1 group max | <1% |
| — | ||
| CVE-2022-24083 | Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks. Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2022-24082 | If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is not properly If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is not properly configured, then it may be possible to upload serialized payloads to attack the underlying system. This does not affect systems running on PegaCloud due to its design and architecture. NVD description · AI analysis pending | 9.8 | 12% | PoC |
| — | |
| CVE-2021-27654 | Forgotten password reset functionality for local accounts can be used to bypass local authentication checks. Forgotten password reset functionality for local accounts can be used to bypass local authentication checks. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2021-43561 | An XSS issue was discovered in the google_for_jobs (aka Google for Jobs) extension before 1.5.1 and 2.x before 2.1.1 for TYPO3. An XSS issue was discovered in the google_for_jobs (aka Google for Jobs) extension before 1.5.1 and 2.x before 2.1.1 for TYPO3. The extension fails to properly encode user input for output in HTML context. A TYPO3 backend user account is required to exploit the vulnerability. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2021-27651 | In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication checks. In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication checks. NVD description · AI analysis pending | 9.8 | 54% |
| — | ||
| CVE-2020-15390 | pyActivity in Pega Platform 8.4.0.237 has a security misconfiguration that leads to an improper access control vulnerability via =GetWebInfo. pyActivity in Pega Platform 8.4.0.237 has a security misconfiguration that leads to an improper access control vulnerability via =GetWebInfo. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2021-27653 | Misconfiguration of the Pega Chat Access Group portal in Pega platform 7.4.0 - 8.5.x could lead to unintended data exposure. Misconfiguration of the Pega Chat Access Group portal in Pega platform 7.4.0 - 8.5.x could lead to unintended data exposure. NVD description · AI analysis pending | 4.9 | 1% | PoC |
| — | |
| CVE-2020-23957 | Pega Platform through 8.4.x is affected by Cross Site Scripting (XSS) via the ConnectionID parameter, as demonstrated by a pyActivity=Data-TRACERSettings.pzStar Pega Platform through 8.4.x is affected by Cross Site Scripting (XSS) via the ConnectionID parameter, as demonstrated by a pyActivity=Data-TRACERSettings.pzStartTracerSession request to a PRAuth URI. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2020-24353 | Pega Platform before 8.4.0 has a XSS issue via stream rule parameters used in the request header. Pega Platform before 8.4.0 has a XSS issue via stream rule parameters used in the request header. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2019-16374 | Pega Platform 8.2.1 allows LDAP injection because a username can contain a * character and can be of unlimited length. Pega Platform 8.2.1 allows LDAP injection because a username can contain a * character and can be of unlimited length. An attacker can specify four characters of a username, followed by the * character, to bypass access control. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2020-8775 +1 in the same advisory: …8773 | Pega Platform before version 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the comment tags. Pega Platform before version 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the comment tags. NVD description · AI analysis pending | 8.9 | <1% |
| — | ||
| CVE-2020-8774 | Pega Platform before version 8.2.6 is affected by a Reflected Cross-Site Scripting vulnerability in the "ActionStringID" function. Pega Platform before version 8.2.6 is affected by a Reflected Cross-Site Scripting vulnerability in the "ActionStringID" function. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2019-16387 | PEGA Platform 8.3.0 is vulnerable to a direct prweb/sso/random_token/!STANDARD?pyActivity=Data-Admin-DB-Name.DBSchema_ListDatabases request while using a low-pr PEGA Platform 8.3.0 is vulnerable to a direct prweb/sso/random_token/!STANDARD?pyActivity=Data-Admin-DB-Name.DBSchema_ListDatabases request while using a low-privilege account. (This can perform actions and retrieve data that only an administrator should have access to.) NOTE: The vendor states that this vulnerability was discovered using an administrator account and they are normal administrator functions. Therefore, the claim that the CVE was done with a low privilege account is incorrect NVD description · AI analysis pending | 8.1 group max | 1% | PoC |
| — | |
| CVE-2017-17478 | An XSS issue was discovered in Designer Studio in Pegasystems Pega Platform 7.1.7, 7.1.8, 7.1.9, 7.1.10, 7.2, 7.2.1, and 7.2.2. An XSS issue was discovered in Designer Studio in Pegasystems Pega Platform 7.1.7, 7.1.8, 7.1.9, 7.1.10, 7.2, 7.2.1, and 7.2.2. A user with developer credentials can insert malicious code (up to 64 characters) into a text field in Designer Studio, after establishing context. Designer Studio is the developer workbench for Pega Platform. That XSS payload will execute when other developers visit the affected pages. NVD description · AI analysis pending | 4.8 | <1% |
| — | ||
| CVE-2017-11356 | The application distribution export functionality in PEGA Platform 7.2 ML0 and earlier allows remote authenticated users with certain privileges to obtain sensi The application distribution export functionality in PEGA Platform 7.2 ML0 and earlier allows remote authenticated users with certain privileges to obtain sensitive configuration information by leveraging a missing access control. NVD description · AI analysis pending | 6.5 | 4% |
| — |