← Back

Pega

pega

50 CVEs • 4 products

Products (4)

Click to collapse
Toggle
Pega Platform
pega_platform
Infinity
infinity
Platform
platform

CVEs (50)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pega
1Pega Platform
Jul 21, 2026
Jul 15, 2026
4.8 MEDIUM· v4
4.8 MEDIUM· v3
N/A· v2
Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
1Pega
1Pega Platform
Jul 21, 2026
Jul 15, 2026
4.6 MEDIUM· v4
4.8 MEDIUM· v3
N/A· v2
Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
1Pega
1Pega Platform
Jun 17, 2026
Apr 15, 2026
4.8 MEDIUM· v4
4.8 MEDIUM· v3
N/A· v2
Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerability in a user interface component. Requires a high privileged user with a developer role.
1Pega
1Pega Platform
Jun 17, 2026
Apr 15, 2026
5.1 MEDIUM· v4
4.8 MEDIUM· v3
N/A· v2
Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface component. Requires a high privileged user with a developer role.
1Pega
1Pega Platform
Jul 24, 2026
Mar 31, 2026
4.8 MEDIUM· v4
3.4 LOW· v3
N/A· v2
Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to Confide...Show more
Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to Confidentiality is low and Integrity is none.Show less
1Pega
1Pega Platform
Jun 17, 2026
Oct 16, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user interface component that can only be used to read data.
1Pega
1Pega Platform
Jun 17, 2026
Sep 10, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component.  Requires a high privileged user with a developer role.
1Pega
1Pega Platform
Jun 17, 2026
Apr 14, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Pega Platform versions 7.2.1 to Infinity 24.2.1 are affected by an XSS issue with Mashup
1Pega
1Pega Platform
Jun 17, 2026
Apr 14, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Pega Platform versions 8.4.3 to Infinity 24.2.1 are affected by an XSS issue with Mashup
1Pega
1Pega Platform
Jun 17, 2026
Jan 13, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile.
1Pega
1Infinity
Jun 17, 2026
Dec 5, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search.
1Pega
1Infinity
Jun 17, 2026
Nov 20, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Pega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of Code
1Pega
1Infinity
Jun 17, 2026
Sep 12, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage.
1Pega
1Infinity
Jun 17, 2026
Sep 12, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with case type.
1Pega
1Infinity
Jun 17, 2026
Sep 12, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with App name.
1Pega
1Pega Platform
Jun 17, 2026
Mar 14, 2024
N/A· v4
7.7 HIGH· v3
N/A· v2
Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation.
1Pega
1Pega Platform
Jun 17, 2026
Mar 6, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content.
1Pega
1Platform
Jun 17, 2026
Jan 31, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Pega Platform from 8.5.4 to 8.8.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.
1Pega
1Platform
Jun 17, 2026
Jan 31, 2024
N/A· v4
8.6 HIGH· v3
N/A· v2
Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents.
1Pega
1Platform
Jun 17, 2026
Oct 18, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Pega Platform versions 8.1 to 8.8.2 are affected by an XSS issue with Pin description