Pega Platform

Pegasystems · 29 CVEs

CVE-2026-1563
MEDIUM

Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a…

Jul 15, 2026

CVE-2026-1562
MEDIUM

Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a use…

Jul 15, 2026

CVE-2026-1711
MEDIUM

Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerability in a user inter…

Apr 15, 2026

CVE-2026-1564
MEDIUM

Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface compone…

Apr 15, 2026

CVE-2025-62184
MEDIUM

Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user inter…

Mar 31, 2026

CVE-2025-9559
MEDIUM

Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user inte…

Oct 16, 2025

CVE-2025-8681
MEDIUM

Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component

Sep 10, 2025

CVE-2025-2161
HIGH

Pega Platform versions 7.2.1 to Infinity 24.2.1 are affected by an XSS issue with Mashup

Apr 14, 2025

CVE-2025-2160
HIGH

Pega Platform versions 8.4.3 to Infinity 24.2.1 are affected by an XSS issue with Mashup

Apr 14, 2025

CVE-2024-12211
MEDIUM

Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile.

Jan 13, 2025

CVE-2023-50168
HIGH

Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation.

Mar 14, 2024

CVE-2023-50167
MEDIUM

Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content.

Mar 6, 2024

CVE-2023-50166
MEDIUM

Pega Platform from 8.5.4 to 8.8.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.

Jan 31, 2024

CVE-2023-50165
HIGH

Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents.

Jan 31, 2024

CVE-2023-32089
MEDIUM

Pega Platform versions 8.1 to 8.8.2 are affected by an XSS issue with Pin description

Oct 18, 2023

CVE-2023-32088
MEDIUM

Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with ad-hoc case creation

Oct 18, 2023

CVE-2023-32087
MEDIUM

Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with task creation

Oct 18, 2023

CVE-2023-4843
MEDIUM

Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Busine…

Sep 8, 2023

CVE-2023-32090
CRITICAL

Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials

Aug 7, 2023

CVE-2023-28094
CRITICAL

Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be uti…

Jun 22, 2023

CVE-2023-26465
MEDIUM

Pega Platform versions 7.2 to 8.8.1 are affected by an XSS issue.

Jun 9, 2023

CVE-2022-35656
MEDIUM

Pega Platform from 8.3 to 8.7.3 vulnerability may allow authenticated security administrators to alter CSRF settings di…

Aug 22, 2022

CVE-2022-35655
MEDIUM

Pega Platform from 7.3 to 8.7.3 is affected by an XSS issue due to a misconfiguration of a datapage setting.

Aug 22, 2022

CVE-2022-35654
MEDIUM

Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.

Aug 22, 2022

CVE-2020-15390
CRITICAL

pyActivity in Pega Platform 8.4.0.237 has a security misconfiguration that leads to an improper access control vulnerab…

Apr 12, 2021

Showing 1 to 25 of 29 CVEs