ZeroHour

Vulnerabilities

51 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-1563
+1 in the same advisory: …1562
Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component.

Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.

NVD description · AI analysis pending
4.8
group max
<1%
  • pega pega platform
CVE-2026-1564
+1 in the same advisory: …1711
Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface component.

Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface component. Requires a high privileged user with a developer role.

NVD description · AI analysis pending
5.1
group max
<1%
  • pega pega platform
CVE-2025-62184
Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interface component.

Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to Confidentiality is low and Integrity is none.

NVD description · AI analysis pending
4.8<1%
  • pega pega platform
CVE-2025-9559
Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user interface component that can only be used to

Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user interface component that can only be used to read data.

NVD description · AI analysis pending
6.5<1%
  • pega pega platform
CVE-2025-8681
Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component.

Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component. Requires a high privileged user with a developer role.

NVD description · AI analysis pending
5.4<1%
  • pega pega platform
CVE-2025-2161
+1 in the same advisory: …2160
Pega Platform versions 7.2.1 to Infinity 24.2.1 are affected by an XSS issue with Mashup

Pega Platform versions 7.2.1 to Infinity 24.2.1 are affected by an XSS issue with Mashup

NVD description · AI analysis pending
6.1<1%
  • pega pega platform
CVE-2024-12211
Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile.

Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile.

NVD description · AI analysis pending
5.4<1%
  • pega pega platform
CVE-2024-10716
Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search.

Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search.

NVD description · AI analysis pending
4.8<1%
  • pega infinity
CVE-2024-10094
Pega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of Code

Pega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of Code

NVD description · AI analysis pending
9.8<1%
  • pega infinity
CVE-2024-6702
+2 in the same advisory: …6701 …6700
Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage.

Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage.

NVD description · AI analysis pending
4.8<1%
  • pega infinity
CVE-2023-50168
Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation.

Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation.

NVD description · AI analysis pending
7.7<1%
  • pega pega platform
CVE-2023-50167
Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content.

Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content.

NVD description · AI analysis pending
6.1<1%
  • pega pega platform
CVE-2023-50165
+1 in the same advisory: …50166
Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents.

Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents.

NVD description · AI analysis pending
8.6
group max
<1%
  • pega platform
CVE-2023-32089
+2 in the same advisory: …32088 …32087
Pega Platform versions 8.1 to 8.8.2 are affected by an XSS issue with Pin description

Pega Platform versions 8.1 to 8.8.2 are affected by an XSS issue with Pin description

NVD description · AI analysis pending
6.1<1%
  • pega platform
CVE-2023-4843
Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Business Director, however this field can only

Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Business Director, however this field can only be modified by an authenticated administrative user.

NVD description · AI analysis pending
4.8<1%
  • pega pega platform
CVE-2023-32090
Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials

Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials

NVD description · AI analysis pending
9.8<1%
  • pega pega platform
CVE-2023-28094
Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default credentials.

Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default credentials.

NVD description · AI analysis pending
9.8<1%
  • pega pega platform
CVE-2023-26465
Pega Platform versions 7.2 to 8.8.1 are affected by an XSS issue.

Pega Platform versions 7.2 to 8.8.1 are affected by an XSS issue.

NVD description · AI analysis pending
6.1<1%
  • pega pega platform
CVE-2023-26466
+2 in the same advisory: …28093 …26467
A user with non-Admin access can change a configuration file on the client to modify the Server URL.

A user with non-Admin access can change a configuration file on the client to modify the Server URL.

NVD description · AI analysis pending
7.8
group max
<1%
  • pega synchronization engine
CVE-2022-35654
+2 in the same advisory: …35655 …35656
Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.

Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.

NVD description · AI analysis pending
6.1
group max
<1%
  • pega pega platform
CVE-2022-24083
Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks.

Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks.

NVD description · AI analysis pending
9.8<1%
  • pega infinity
CVE-2022-24082
If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is not properly

If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is not properly configured, then it may be possible to upload serialized payloads to attack the underlying system. This does not affect systems running on PegaCloud due to its design and architecture.

NVD description · AI analysis pending
9.812% PoC
  • pega infinity
CVE-2021-27654
Forgotten password reset functionality for local accounts can be used to bypass local authentication checks.

Forgotten password reset functionality for local accounts can be used to bypass local authentication checks.

NVD description · AI analysis pending
7.8<1%
  • pega infinity
CVE-2021-43561
An XSS issue was discovered in the google_for_jobs (aka Google for Jobs) extension before 1.5.1 and 2.x before 2.1.1 for TYPO3.

An XSS issue was discovered in the google_for_jobs (aka Google for Jobs) extension before 1.5.1 and 2.x before 2.1.1 for TYPO3. The extension fails to properly encode user input for output in HTML context. A TYPO3 backend user account is required to exploit the vulnerability.

NVD description · AI analysis pending
5.4<1%
  • pega-sus google for jobs
CVE-2021-27651
In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication checks.

In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication checks.

NVD description · AI analysis pending
9.854%
  • pega infinity
CVE-2020-15390
pyActivity in Pega Platform 8.4.0.237 has a security misconfiguration that leads to an improper access control vulnerability via =GetWebInfo.

pyActivity in Pega Platform 8.4.0.237 has a security misconfiguration that leads to an improper access control vulnerability via =GetWebInfo.

NVD description · AI analysis pending
9.81% PoC
  • pega pega platform
CVE-2021-27653
Misconfiguration of the Pega Chat Access Group portal in Pega platform 7.4.0 - 8.5.x could lead to unintended data exposure.

Misconfiguration of the Pega Chat Access Group portal in Pega platform 7.4.0 - 8.5.x could lead to unintended data exposure.

NVD description · AI analysis pending
4.91% PoC
  • pega infinity
CVE-2020-23957
Pega Platform through 8.4.x is affected by Cross Site Scripting (XSS) via the ConnectionID parameter, as demonstrated by a pyActivity=Data-TRACERSettings.pzStar

Pega Platform through 8.4.x is affected by Cross Site Scripting (XSS) via the ConnectionID parameter, as demonstrated by a pyActivity=Data-TRACERSettings.pzStartTracerSession request to a PRAuth URI.

NVD description · AI analysis pending
6.1<1% PoC
  • pega pega platform
CVE-2020-24353
Pega Platform before 8.4.0 has a XSS issue via stream rule parameters used in the request header.

Pega Platform before 8.4.0 has a XSS issue via stream rule parameters used in the request header.

NVD description · AI analysis pending
6.1<1%
  • pega pega platform
CVE-2019-16374
Pega Platform 8.2.1 allows LDAP injection because a username can contain a * character and can be of unlimited length.

Pega Platform 8.2.1 allows LDAP injection because a username can contain a * character and can be of unlimited length. An attacker can specify four characters of a username, followed by the * character, to bypass access control.

NVD description · AI analysis pending
9.82%
  • pega platform
CVE-2020-8775
+1 in the same advisory: …8773
Pega Platform before version 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the comment tags.

Pega Platform before version 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the comment tags.

NVD description · AI analysis pending
8.9<1%
  • pega platform
CVE-2020-8774
Pega Platform before version 8.2.6 is affected by a Reflected Cross-Site Scripting vulnerability in the "ActionStringID" function.

Pega Platform before version 8.2.6 is affected by a Reflected Cross-Site Scripting vulnerability in the "ActionStringID" function.

NVD description · AI analysis pending
8.8<1%
  • pega pega platform
CVE-2019-16387
+2 in the same advisory: …16386 …16388
PEGA Platform 8.3.0 is vulnerable to a direct prweb/sso/random_token/!STANDARD?pyActivity=Data-Admin-DB-Name.DBSchema_ListDatabases request while using a low-pr

PEGA Platform 8.3.0 is vulnerable to a direct prweb/sso/random_token/!STANDARD?pyActivity=Data-Admin-DB-Name.DBSchema_ListDatabases request while using a low-privilege account. (This can perform actions and retrieve data that only an administrator should have access to.) NOTE: The vendor states that this vulnerability was discovered using an administrator account and they are normal administrator functions. Therefore, the claim that the CVE was done with a low privilege account is incorrect

NVD description · AI analysis pending
8.1
group max
1% PoC
  • pega pega platform
CVE-2017-17478
An XSS issue was discovered in Designer Studio in Pegasystems Pega Platform 7.1.7, 7.1.8, 7.1.9, 7.1.10, 7.2, 7.2.1, and 7.2.2.

An XSS issue was discovered in Designer Studio in Pegasystems Pega Platform 7.1.7, 7.1.8, 7.1.9, 7.1.10, 7.2, 7.2.1, and 7.2.2. A user with developer credentials can insert malicious code (up to 64 characters) into a text field in Designer Studio, after establishing context. Designer Studio is the developer workbench for Pega Platform. That XSS payload will execute when other developers visit the affected pages.

NVD description · AI analysis pending
4.8<1%
  • pega pega platform
CVE-2017-11356
The application distribution export functionality in PEGA Platform 7.2 ML0 and earlier allows remote authenticated users with certain privileges to obtain sensi

The application distribution export functionality in PEGA Platform 7.2 ML0 and earlier allows remote authenticated users with certain privileges to obtain sensitive configuration information by leveraging a missing access control.

NVD description · AI analysis pending
6.54%
  • pega pega platform