← Back

Pega Platform

pega_platform

Vendor: Pega • 29 CVEs

CVEs (29)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pega
1Pega Platform
Jul 21, 2026
Jul 15, 2026
4.8 MEDIUM· v4
4.8 MEDIUM· v3
N/A· v2
Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
1Pega
1Pega Platform
Jul 21, 2026
Jul 15, 2026
4.6 MEDIUM· v4
4.8 MEDIUM· v3
N/A· v2
Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
1Pega
1Pega Platform
Jun 17, 2026
Apr 15, 2026
4.8 MEDIUM· v4
4.8 MEDIUM· v3
N/A· v2
Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerability in a user interface component. Requires a high privileged user with a developer role.
1Pega
1Pega Platform
Jun 17, 2026
Apr 15, 2026
5.1 MEDIUM· v4
4.8 MEDIUM· v3
N/A· v2
Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface component. Requires a high privileged user with a developer role.
1Pega
1Pega Platform
Jul 24, 2026
Mar 31, 2026
4.8 MEDIUM· v4
3.4 LOW· v3
N/A· v2
Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to Confide...Show more
Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to Confidentiality is low and Integrity is none.Show less
1Pega
1Pega Platform
Jun 17, 2026
Oct 16, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user interface component that can only be used to read data.
1Pega
1Pega Platform
Jun 17, 2026
Sep 10, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component.  Requires a high privileged user with a developer role.
1Pega
1Pega Platform
Jun 17, 2026
Apr 14, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Pega Platform versions 7.2.1 to Infinity 24.2.1 are affected by an XSS issue with Mashup
1Pega
1Pega Platform
Jun 17, 2026
Apr 14, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Pega Platform versions 8.4.3 to Infinity 24.2.1 are affected by an XSS issue with Mashup
1Pega
1Pega Platform
Jun 17, 2026
Jan 13, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile.
1Pega
1Pega Platform
Jun 17, 2026
Mar 14, 2024
N/A· v4
7.7 HIGH· v3
N/A· v2
Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation.
1Pega
1Pega Platform
Jun 17, 2026
Mar 6, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content.
1Pega
1Pega Platform
Jun 17, 2026
Sep 8, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Business Director, however this field can only be modified by an authenticated administrative user.
1Pega
1Pega Platform
Jun 17, 2026
Aug 7, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials
1Pega
1Pega Platform
Jun 17, 2026
Jun 22, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default credentials.
1Pega
1Pega Platform
Jun 17, 2026
Jun 9, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Pega Platform versions 7.2 to 8.8.1 are affected by an XSS issue.
1Pega
1Pega Platform
Jun 17, 2026
Aug 22, 2022
N/A· v4
4.5 MEDIUM· v3
N/A· v2
Pega Platform from 8.3 to 8.7.3 vulnerability may allow authenticated security administrators to alter CSRF settings directly.
1Pega
1Pega Platform
Jun 17, 2026
Aug 22, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Pega Platform from 7.3 to 8.7.3 is affected by an XSS issue due to a misconfiguration of a datapage setting.
1Pega
1Pega Platform
Jun 17, 2026
Aug 22, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.
1Pega
1Pega Platform
Jun 17, 2026
Apr 12, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
pyActivity in Pega Platform 8.4.0.237 has a security misconfiguration that leads to an improper access control vulnerability via =GetWebInfo.