Pega Platform
Pegasystems · 29 CVEs
Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a…
Jul 15, 2026
Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a use…
Jul 15, 2026
Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerability in a user inter…
Apr 15, 2026
Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface compone…
Apr 15, 2026
Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user inter…
Mar 31, 2026
Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user inte…
Oct 16, 2025
Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component
Sep 10, 2025
Pega Platform versions 7.2.1 to Infinity 24.2.1 are affected by an XSS issue with Mashup
Apr 14, 2025
Pega Platform versions 8.4.3 to Infinity 24.2.1 are affected by an XSS issue with Mashup
Apr 14, 2025
Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile.
Jan 13, 2025
Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation.
Mar 14, 2024
Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content.
Mar 6, 2024
Pega Platform from 8.5.4 to 8.8.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.
Jan 31, 2024
Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents.
Jan 31, 2024
Pega Platform versions 8.1 to 8.8.2 are affected by an XSS issue with Pin description
Oct 18, 2023
Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with ad-hoc case creation
Oct 18, 2023
Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with task creation
Oct 18, 2023
Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Busine…
Sep 8, 2023
Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials
Aug 7, 2023
Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be uti…
Jun 22, 2023
Pega Platform versions 7.2 to 8.8.1 are affected by an XSS issue.
Jun 9, 2023
Pega Platform from 8.3 to 8.7.3 vulnerability may allow authenticated security administrators to alter CSRF settings di…
Aug 22, 2022
Pega Platform from 7.3 to 8.7.3 is affected by an XSS issue due to a misconfiguration of a datapage setting.
Aug 22, 2022
Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.
Aug 22, 2022
pyActivity in Pega Platform 8.4.0.237 has a security misconfiguration that leads to an improper access control vulnerab…
Apr 12, 2021
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-1563 | Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a hig… | MEDIUM | 0.24% | Jul 15, 2026 |
| CVE-2026-1562 | Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high p… | MEDIUM | 0.24% | Jul 15, 2026 |
| CVE-2026-1711 | Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerability in a user interface component. Requires a high privileg… | MEDIUM | 0.19% | Apr 15, 2026 |
| CVE-2026-1564 | Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface component. Requires a high privileged user with… | MEDIUM | 0.19% | Apr 15, 2026 |
| CVE-2025-62184 | Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. | MEDIUM | 0.26% | Mar 31, 2026 |
| CVE-2025-9559 | Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user interface component that can only be used to… | MEDIUM | 0.40% | Oct 16, 2025 |
| CVE-2025-8681 | Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component | MEDIUM | 0.19% | Sep 10, 2025 |
| CVE-2025-2161 | Pega Platform versions 7.2.1 to Infinity 24.2.1 are affected by an XSS issue with Mashup | HIGH | 0.28% | Apr 14, 2025 |
| CVE-2025-2160 | Pega Platform versions 8.4.3 to Infinity 24.2.1 are affected by an XSS issue with Mashup | HIGH | 0.28% | Apr 14, 2025 |
| CVE-2024-12211 | Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile. | MEDIUM | 0.32% | Jan 13, 2025 |
| CVE-2023-50168 | Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation. | HIGH | 0.39% | Mar 14, 2024 |
| CVE-2023-50167 | Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content. | MEDIUM | 0.30% | Mar 6, 2024 |
| CVE-2023-50166 | Pega Platform from 8.5.4 to 8.8.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter. | MEDIUM | 0.34% | Jan 31, 2024 |
| CVE-2023-50165 | Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents. | HIGH | 0.34% | Jan 31, 2024 |
| CVE-2023-32089 | Pega Platform versions 8.1 to 8.8.2 are affected by an XSS issue with Pin description | MEDIUM | 0.30% | Oct 18, 2023 |
| CVE-2023-32088 | Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with ad-hoc case creation | MEDIUM | 0.30% | Oct 18, 2023 |
| CVE-2023-32087 | Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with task creation | MEDIUM | 0.30% | Oct 18, 2023 |
| CVE-2023-4843 | Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Business Director, however this field can only… | MEDIUM | 0.34% | Sep 8, 2023 |
| CVE-2023-32090 | Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials | CRITICAL | 0.62% | Aug 7, 2023 |
| CVE-2023-28094 | Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default credentials. | CRITICAL | 0.53% | Jun 22, 2023 |
| CVE-2023-26465 | Pega Platform versions 7.2 to 8.8.1 are affected by an XSS issue. | MEDIUM | 0.44% | Jun 9, 2023 |
| CVE-2022-35656 | Pega Platform from 8.3 to 8.7.3 vulnerability may allow authenticated security administrators to alter CSRF settings directly. | MEDIUM | 0.33% | Aug 22, 2022 |
| CVE-2022-35655 | Pega Platform from 7.3 to 8.7.3 is affected by an XSS issue due to a misconfiguration of a datapage setting. | MEDIUM | 0.47% | Aug 22, 2022 |
| CVE-2022-35654 | Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter. | MEDIUM | 0.52% | Aug 22, 2022 |
| CVE-2020-15390 | pyActivity in Pega Platform 8.4.0.237 has a security misconfiguration that leads to an improper access control vulnerability via =GetWebInfo. | CRITICAL | 1.35% | Apr 12, 2021 |
Showing 1 to 25 of 29 CVEs