VendorsPegapega_platformall versions
Vulnerabilities

Pega Platform

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

29CVEs
CVE-2020-15390
pyActivity in Pega Platform 8.4.0.237 has a security misconfiguration that leads to an improper access control vulnerability via =GetWebInfo.
Published 2021-04-12 · Modified
9.8EPSS 0.013
CVE-2023-32090
Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials
Published 2023-08-07 · Modified
9.8EPSS 0.006
CVE-2023-28094
Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default credentials.
Published 2023-06-22 · Modified
9.8EPSS 0.005
CVE-2020-8774
Pega Platform before version 8.2.6 is affected by a Reflected Cross-Site Scripting vulnerability in the "ActionStringID" function.
Published 2020-04-29 · Modified
8.8EPSS 0.008
CVE-2019-16387
PEGA Platform 8.3.0 is vulnerable to a direct prweb/sso/random_token/!STANDARD?pyActivity=Data-Admin-DB-Name.DBSchema_ListDatabases request while using a low-privilege account. (This can perform actions and retrieve data that only an administrator should have access to.) NOTE: The vendor states that this vulnerability was discovered using an administrator account and they are normal administrator functions. Therefore, the claim that the CVE was done with a low privilege account is incorrect
Published 2019-11-26 · Modified
8.1EPSS 0.010
CVE-2025-2160
Pega Platform versions 8.4.3 to Infinity 24.2.1 are affected by an XSS issue with Mashup
Published 2025-04-14 · Analyzed
8.1EPSS 0.003
CVE-2023-26465
Pega Platform versions 7.2 to 8.8.1 are affected by an XSS issue.
Published 2023-06-09 · Modified
8.0EPSS 0.004
CVE-2023-50168
Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation.
Published 2024-03-14 · Analyzed
7.7EPSS 0.004
CVE-2025-2161
Pega Platform versions 7.2.1 to Infinity 24.2.1 are affected by an XSS issue with Mashup
Published 2025-04-14 · Analyzed
7.1EPSS 0.003
CVE-2022-35656
Pega Platform from 8.3 to 8.7.3 vulnerability may allow authenticated security administrators to alter CSRF settings directly.
Published 2022-08-22 · Modified
6.8EPSS 0.003
CVE-2017-11356
The application distribution export functionality in PEGA Platform 7.2 ML0 and earlier allows remote authenticated users with certain privileges to obtain sensitive configuration information by leveraging a missing access control.
Published 2017-08-02 · Modified
6.51 PoCEPSS 0.035
CVE-2025-9559
Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user interface component that can only be used to read data
Published 2025-10-16 · Analyzed
6.5EPSS 0.004
CVE-2017-11355
Multiple cross-site scripting (XSS) vulnerabilities in PEGA Platform 7.2 ML0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to the main page; the (2) beanReference parameter to the JavaBean viewer page; or the (3) pyTableName to the System database schema modification page.
Published 2017-08-02 · Modified
6.11 PoCEPSS 0.029
CVE-2020-23957
Pega Platform through 8.4.x is affected by Cross Site Scripting (XSS) via the ConnectionID parameter, as demonstrated by a pyActivity=Data-TRACERSettings.pzStartTracerSession request to a PRAuth URI.
Published 2020-12-15 · Modified
6.1EPSS 0.007
CVE-2020-24353
Pega Platform before 8.4.0 has a XSS issue via stream rule parameters used in the request header.
Published 2020-11-09 · Modified
6.1EPSS 0.006
CVE-2022-35654
Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.
Published 2022-08-22 · Modified
6.1EPSS 0.005
CVE-2022-35655
Pega Platform from 7.3 to 8.7.3 is affected by an XSS issue due to a misconfiguration of a datapage setting.
Published 2022-08-22 · Modified
6.1EPSS 0.005
CVE-2023-50167
Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content.
Published 2024-03-06 · Analyzed
6.1EPSS 0.003
CVE-2025-8681
Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component
Published 2025-09-10 · Analyzed
5.5EPSS 0.002
CVE-2024-12211
Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile.
Published 2025-01-13 · Analyzed
5.4EPSS 0.003
CVE-2026-1564
Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface component. Requires a high privileged user with a developer role.
Published 2026-04-15 · Analyzed
5.1EPSS 0.002
CVE-2017-17478
An XSS issue was discovered in Designer Studio in Pegasystems Pega Platform 7.1.7, 7.1.8, 7.1.9, 7.1.10, 7.2, 7.2.1, and 7.2.2. A user with developer credentials can insert malicious code (up to 64 characters) into a text field in Designer Studio, after establishing context. Designer Studio is the developer workbench for Pega Platform. That XSS payload will execute when other developers visit the affected pages.
Published 2018-02-27 · Modified
4.8EPSS 0.005
CVE-2023-4843
Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Business Director, however this field can only be modified by an authenticated administrative user.
Published 2023-09-08 · Modified
4.8EPSS 0.003
CVE-2025-62184
Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interface component.
Published 2026-03-31 · Analyzed
4.8EPSS 0.003
CVE-2026-1562
Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
Published 2026-07-15 · Analyzed
4.8EPSS 0.002
CVE-2026-1563
Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
Published 2026-07-15 · Analyzed
4.8EPSS 0.002
CVE-2026-1711
Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerability in a user interface component. Requires a high privileged user with a developer role.
Published 2026-04-15 · Analyzed
4.8EPSS 0.002
CVE-2019-16386
PEGA Platform 7.x and 8.x is vulnerable to Information disclosure via a direct prweb/sso/random_token/!STANDARD?pyActivity=GetWebInfo&target=popup&pzHarnessID=random_harness_id request to get database schema information while using a low-privilege account. NOTE: The vendor states that this vulnerability was discovered using an administrator account and they are normal administrator functions. Therefore, the claim that the CVE was done with a low privilege account is incorrect
Published 2019-11-26 · Modified
4.3EPSS 0.008
CVE-2019-16388
PEGA Platform 8.3.0 is vulnerable to Information disclosure via a direct prweb/sso/random_token/!STANDARD?pyStream=MyAlerts request to get Audit Log information while using a low-privilege account. NOTE: The vendor states that this vulnerability was discovered using an administrator account and they are normal administrator functions. Therefore, the claim that the CVE was done with a low privilege account is incorrect
Published 2019-11-26 · Modified
4.3EPSS 0.007