CVE-2025-62184

Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to Confidentiality is low and Integrity is none.
Configurations

Configuration 1 (hide)

cpe:2.3:a:pega:pega_platform:*:*:*:*:*:*:*:*

History

03 Apr 2026, 12:49

Type Values Removed Values Added
First Time Pega pega Platform
Pega
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 3.4
CPE cpe:2.3:a:pega:pega_platform:*:*:*:*:*:*:*:*
References () https://support.pega.com/support-doc/pega-security-advisory-o25-vulnerability-remediation-noteĀ - () https://support.pega.com/support-doc/pega-security-advisory-o25-vulnerability-remediation-noteĀ - Vendor Advisory

31 Mar 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-31 18:16

Updated : 2026-04-03 12:49


NVD link : CVE-2025-62184

Mitre link : CVE-2025-62184

CVE.ORG link : CVE-2025-62184


JSON object : View

Products Affected

pega

  • pega_platform
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')