Filtered by vendor Pega
Subscribe
Total
48 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-1711 | 1 Pega | 1 Pega Platform | 2026-06-17 | N/A | 4.8 MEDIUM |
| Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerability in a user interface component. Requires a high privileged user with a developer role. | |||||
| CVE-2026-1564 | 1 Pega | 1 Pega Platform | 2026-06-17 | N/A | 4.8 MEDIUM |
| Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface component. Requires a high privileged user with a developer role. | |||||
| CVE-2025-9559 | 1 Pega | 1 Pega Platform | 2026-06-17 | N/A | 6.5 MEDIUM |
| Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user interface component that can only be used to read data. | |||||
| CVE-2025-8681 | 1 Pega | 1 Pega Platform | 2026-06-17 | N/A | 5.5 MEDIUM |
| Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component. Â Requires a high privileged user with a developer role. | |||||
| CVE-2025-62184 | 1 Pega | 1 Pega Platform | 2026-06-17 | N/A | 3.4 LOW |
| Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to Confidentiality is low and Integrity is none. | |||||
| CVE-2025-2161 | 1 Pega | 1 Pega Platform | 2026-06-17 | N/A | 7.1 HIGH |
| Pega Platform versions 7.2.1 to Infinity 24.2.1 are affected by an XSS issue with Mashup | |||||
| CVE-2025-2160 | 1 Pega | 1 Pega Platform | 2026-06-17 | N/A | 8.1 HIGH |
| Pega Platform versions 8.4.3 to Infinity 24.2.1 are affected by an XSS issue with Mashup | |||||
| CVE-2024-6702 | 1 Pega | 1 Infinity | 2026-06-17 | N/A | 5.2 MEDIUM |
| Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage. | |||||
| CVE-2024-6701 | 1 Pega | 1 Infinity | 2026-06-17 | N/A | 5.5 MEDIUM |
| Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with case type. | |||||
| CVE-2024-6700 | 1 Pega | 1 Infinity | 2026-06-17 | N/A | 5.5 MEDIUM |
| Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with App name. | |||||
| CVE-2024-12211 | 1 Pega | 1 Pega Platform | 2026-06-17 | N/A | 5.4 MEDIUM |
| Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile. | |||||
| CVE-2024-10716 | 1 Pega | 1 Infinity | 2026-06-17 | N/A | 5.9 MEDIUM |
| Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search. | |||||
| CVE-2024-10094 | 1 Pega | 1 Infinity | 2026-06-17 | N/A | 9.1 CRITICAL |
| Pega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of Code | |||||
| CVE-2023-50168 | 1 Pega | 1 Pega Platform | 2026-06-17 | N/A | 7.7 HIGH |
| Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation. | |||||
| CVE-2023-50167 | 1 Pega | 1 Pega Platform | 2026-06-17 | N/A | 5.4 MEDIUM |
| Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content. | |||||
| CVE-2023-50166 | 1 Pega | 1 Platform | 2026-06-17 | N/A | 6.1 MEDIUM |
| Pega Platform from 8.5.4 to 8.8.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter. | |||||
| CVE-2023-50165 | 1 Pega | 1 Platform | 2026-06-17 | N/A | 8.5 HIGH |
| Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents. | |||||
| CVE-2023-4843 | 1 Pega | 1 Pega Platform | 2026-06-17 | N/A | 4.3 MEDIUM |
| Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Business Director, however this field can only be modified by an authenticated administrative user. | |||||
| CVE-2023-32090 | 1 Pega | 1 Pega Platform | 2026-06-17 | N/A | 9.8 CRITICAL |
| Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials | |||||
| CVE-2023-32089 | 1 Pega | 1 Platform | 2026-06-17 | N/A | 4.6 MEDIUM |
| Pega Platform versions 8.1 to 8.8.2 are affected by an XSS issue with Pin description | |||||
