VYPR

Vendor CVEs

Pega

All CVEs

59 total · sorted by risk
  • CVE-2022-35656MedAug 22, 2022
    risk 0.29cvss 4.5epss 0.00

    Pega Platform from 8.3 to 8.7.3 vulnerability may allow authenticated security administrators to alter CSRF settings directly.

  • CVE-2023-4843MedSep 8, 2023
    risk 0.28cvss 4.3epss 0.00

    Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Business Director, however this field can only be modified by an authenticated administrative user.

  • CVE-2019-16388MedNov 26, 2019
    risk 0.28cvss 4.3epss 0.01

    PEGA Platform 8.3.0 is vulnerable to Information disclosure via a direct prweb/sso/random_token/!STANDARD?pyStream=MyAlerts request to get Audit Log information while using a low-privilege account. NOTE: The vendor states that this vulnerability was discovered using an…

  • CVE-2019-16386MedNov 26, 2019
    risk 0.28cvss 4.3epss 0.01

    PEGA Platform 7.x and 8.x is vulnerable to Information disclosure via a direct prweb/sso/random_token/!STANDARD?pyActivity=GetWebInfo&target=popup&pzHarnessID=random_harness_id request to get database schema information while using a low-privilege account. NOTE: The vendor…

  • CVE-2025-62184LowMar 31, 2026
    risk 0.22cvss 3.4epss 0.00

    Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to Confidentiality is low and Integrity is none.

  • CVE-2026-14337MedAug 4, 2026
    risk 0.00cvss epss 0.00

    Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.

  • CVE-2026-1563MedJul 15, 2026
    risk 0.00cvss 4.8epss 0.00

    Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.

  • CVE-2026-1562MedJul 15, 2026
    risk 0.00cvss 4.8epss 0.00

    Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.

  • CVE-2025-62180HigJun 23, 2026
    risk 0.00cvss epss 0.00

    Pega Platform versions 8.3.0 through Infinity 25.1.2 are affected by an authorization weakness that may allow authenticated users to access certain additional data via crafted URLs.

Page 2 of 2