Pega Platform
by Pega
CVEs (51)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-9559 | Med | 0.42 | 6.5 | 0.00 | Oct 16, 2025 | Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user interface component that can only be used to read data. | ||
| CVE-2023-50166 | Med | 0.40 | 6.1 | 0.00 | Jan 31, 2024 | Pega Platform from 8.5.4 to 8.8.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter. | ||
| CVE-2023-26465 | Med | 0.40 | 6.1 | 0.00 | Jun 9, 2023 | Pega Platform versions 7.2 to 8.8.1 are affected by an XSS issue. | ||
| CVE-2022-35655 | Med | 0.40 | 6.1 | 0.00 | Aug 22, 2022 | Pega Platform from 7.3 to 8.7.3 is affected by an XSS issue due to a misconfiguration of a datapage setting. | ||
| CVE-2022-35654 | Med | 0.40 | 6.1 | 0.00 | Aug 22, 2022 | Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter. | ||
| CVE-2020-23957 | Med | 0.40 | 6.1 | 0.01 | Dec 15, 2020 | Pega Platform through 8.4.x is affected by Cross Site Scripting (XSS) via the ConnectionID parameter, as demonstrated by a pyActivity=Data-TRACERSettings.pzStartTracerSession request to a PRAuth URI. | ||
| CVE-2020-24353 | Med | 0.40 | 6.1 | 0.01 | Nov 9, 2020 | Pega Platform before 8.4.0 has a XSS issue via stream rule parameters used in the request header. | ||
| CVE-2024-10716 | Med | 0.38 | 5.9 | 0.00 | Dec 5, 2024 | Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search. | ||
| CVE-2025-8681 | Med | 0.36 | 5.5 | 0.00 | Sep 10, 2025 | Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component. Requires a high privileged user with a developer role. | ||
| CVE-2024-6701 | Med | 0.36 | 5.5 | 0.00 | Sep 12, 2024 | Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with case type. | ||
| CVE-2024-6700 | Med | 0.36 | 5.5 | 0.00 | Sep 12, 2024 | Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with App name. | ||
| CVE-2024-12211 | Med | 0.35 | 5.4 | 0.00 | Jan 13, 2025 | Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile. | ||
| CVE-2023-50167 | Med | 0.35 | 5.4 | 0.00 | Mar 6, 2024 | Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content. | ||
| CVE-2025-62181 | Med | 0.34 | 5.3 | 0.00 | Dec 10, 2025 | Pega Platform versions 7.1.0 through Infinity 25.1.0 are affected by a User Enumeration. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated user to determine if a username is valid or not. This only… | ||
| CVE-2024-6702 | Med | 0.34 | 5.2 | 0.00 | Sep 12, 2024 | Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage. | ||
| CVE-2026-1711 | Med | 0.31 | 4.8 | 0.00 | Apr 15, 2026 | Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerability in a user interface component. Requires a high privileged user with a developer role. | ||
| CVE-2026-1564 | Med | 0.31 | 4.8 | 0.00 | Apr 15, 2026 | Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface component. Requires a high privileged user with a developer role. | ||
| CVE-2025-62183 | Med | 0.31 | — | 0.00 | Feb 17, 2026 | Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to Confidentiality and Integrity are low. | ||
| CVE-2017-17478 | Med | 0.31 | 4.8 | 0.01 | Feb 27, 2018 | An XSS issue was discovered in Designer Studio in Pegasystems Pega Platform 7.1.7, 7.1.8, 7.1.9, 7.1.10, 7.2, 7.2.1, and 7.2.2. A user with developer credentials can insert malicious code (up to 64 characters) into a text field in Designer Studio, after establishing context.… | ||
| CVE-2023-32089 | Med | 0.30 | 4.6 | 0.00 | Oct 18, 2023 | Pega Platform versions 8.1 to 8.8.2 are affected by an XSS issue with Pin description |
- risk 0.42cvss 6.5epss 0.00
Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user interface component that can only be used to read data.
- risk 0.40cvss 6.1epss 0.00
Pega Platform from 8.5.4 to 8.8.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.
- risk 0.40cvss 6.1epss 0.00
Pega Platform versions 7.2 to 8.8.1 are affected by an XSS issue.
- risk 0.40cvss 6.1epss 0.00
Pega Platform from 7.3 to 8.7.3 is affected by an XSS issue due to a misconfiguration of a datapage setting.
- risk 0.40cvss 6.1epss 0.00
Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.
- risk 0.40cvss 6.1epss 0.01
Pega Platform through 8.4.x is affected by Cross Site Scripting (XSS) via the ConnectionID parameter, as demonstrated by a pyActivity=Data-TRACERSettings.pzStartTracerSession request to a PRAuth URI.
- risk 0.40cvss 6.1epss 0.01
Pega Platform before 8.4.0 has a XSS issue via stream rule parameters used in the request header.
- risk 0.38cvss 5.9epss 0.00
Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search.
- risk 0.36cvss 5.5epss 0.00
Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component. Requires a high privileged user with a developer role.
- risk 0.36cvss 5.5epss 0.00
Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with case type.
- risk 0.36cvss 5.5epss 0.00
Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with App name.
- risk 0.35cvss 5.4epss 0.00
Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile.
- risk 0.35cvss 5.4epss 0.00
Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content.
- risk 0.34cvss 5.3epss 0.00
Pega Platform versions 7.1.0 through Infinity 25.1.0 are affected by a User Enumeration. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated user to determine if a username is valid or not. This only…
- risk 0.34cvss 5.2epss 0.00
Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage.
- risk 0.31cvss 4.8epss 0.00
Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerability in a user interface component. Requires a high privileged user with a developer role.
- risk 0.31cvss 4.8epss 0.00
Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface component. Requires a high privileged user with a developer role.
- risk 0.31cvss —epss 0.00
Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to Confidentiality and Integrity are low.
- risk 0.31cvss 4.8epss 0.01
An XSS issue was discovered in Designer Studio in Pegasystems Pega Platform 7.1.7, 7.1.8, 7.1.9, 7.1.10, 7.2, 7.2.1, and 7.2.2. A user with developer credentials can insert malicious code (up to 64 characters) into a text field in Designer Studio, after establishing context.…
- risk 0.30cvss 4.6epss 0.00
Pega Platform versions 8.1 to 8.8.2 are affected by an XSS issue with Pin description
Page 2 of 3