Vulnerability index

Browse CVEs

35 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pega Platform MEDIUM 6.5
CVE-2025-9559

Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user interface component that can only …

Fix: 23.1.5+
Fix from $1,600 2025-10-16
Pega Platform MEDIUM 5.4
CVE-2025-8681

Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component.  Requires a high privileged user wi…

Fix: 23.1.5 / 24.1.3+
Fix from $1,600 2025-09-10
Pega Platform MEDIUM 6.1
CVE-2025-2160

Pega Platform versions 8.4.3 to Infinity 24.2.1 are affected by an XSS issue with Mashup

Fix: 8.5.5 / 23.1.4+
Fix from $1,600 2025-04-14
Pega Platform MEDIUM 6.1
CVE-2025-2161

Pega Platform versions 7.2.1 to Infinity 24.2.1 are affected by an XSS issue with Mashup

Fix: 8.5.5 / 23.1.4+
Fix from $1,600 2025-04-14
Pega Platform MEDIUM 5.4
CVE-2024-12211

Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile.

Fix: 23.1.4 / 24.1.2+
Fix from $1,600 2025-01-13
Infinity CRITICAL 9.8
CVE-2024-10094

Pega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of Code

Fix: 8.1.9 / 8.2.8+
Fix from $2,300 2024-11-20
Pega Platform HIGH 7.7
CVE-2023-50168

Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation.

Fix: 8.8.5+
Fix from $1,950 2024-03-14
Pega Platform MEDIUM 6.1
CVE-2023-50167

Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content.

Fix: 8.8.5+
Fix from $1,600 2024-03-06
Platform HIGH 8.6
CVE-2023-50165

Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents.

Fix: after 23.1.0
Fix from $1,950 2024-01-31
Platform MEDIUM 6.1
CVE-2023-50166

Pega Platform from 8.5.4 to 8.8.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.

Fix: after 8.8.3
Fix from $1,600 2024-01-31
Platform MEDIUM 6.1
CVE-2023-32087

Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with task creation

Fix: 8.7.5 / 8.8.3+
Fix from $1,600 2023-10-18
Platform MEDIUM 6.1
CVE-2023-32088

Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with ad-hoc case creation

Fix: 8.7.5 / 8.8.3+
Fix from $1,600 2023-10-18
Platform MEDIUM 6.1
CVE-2023-32089

Pega Platform versions 8.1 to 8.8.2 are affected by an XSS issue with Pin description

Fix: after 8.8.2
Fix from $1,600 2023-10-18
Pega Platform CRITICAL 9.8
CVE-2023-32090

Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials

Fix: after 7.3.1
Fix from $2,300 2023-08-07
Pega Platform CRITICAL 9.8
CVE-2023-28094

Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default credentials.

Fix: after 8.8.3
Fix from $2,300 2023-06-22
Pega Platform MEDIUM 6.1
CVE-2023-26465

Pega Platform versions 7.2 to 8.8.1 are affected by an XSS issue.

Fix: after 8.8.1
Fix from $1,600 2023-06-09
Synchronization Engine MEDIUM 5.4
CVE-2023-26467

A man in the middle can redirect traffic to a malicious server in a compromised configuration.

Fix: 3.1.30+
Fix from $1,600 2023-04-10
Synchronization Engine HIGH 7.8
CVE-2023-26466

A user with non-Admin access can change a configuration file on the client to modify the Server URL.

Fix: 3.1.30+
Fix from $1,950 2023-04-10
Synchronization Engine MEDIUM 6.5
CVE-2023-28093

A user with a compromised configuration can start an unsigned binary as a service.

Fix: 3.1.30+
Fix from $1,600 2023-04-10
Pega Platform MEDIUM 6.1
CVE-2022-35654

Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.

Fix: after 8.7.3
Fix from $1,600 2022-08-22
Pega Platform MEDIUM 6.1
CVE-2022-35655

Pega Platform from 7.3 to 8.7.3 is affected by an XSS issue due to a misconfiguration of a datapage setting.

Fix: after 8.7.3
Fix from $1,600 2022-08-22
Infinity CRITICAL 9.8
CVE-2022-24083

Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks.

Fix: after 8.7.2
Fix from $2,300 2022-07-25
Infinity CRITICAL 9.8
CVE-2022-24082EPSS 12%

If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is no…

Fix: 8.7.3+
Fix from $2,300 2022-07-19
Infinity HIGH 7.8
CVE-2021-27654

Forgotten password reset functionality for local accounts can be used to bypass local authentication checks.

Fix: after 8.6.1
Fix from $1,950 2022-01-28
Infinity CRITICAL 9.8
CVE-2021-27651EPSS 54%

In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication chec…

Fix: after 8.5.2
Fix from $2,300 2021-04-29
Pega Platform CRITICAL 9.8
CVE-2020-15390

pyActivity in Pega Platform 8.4.0.237 has a security misconfiguration that leads to an improper access control vulnerability via =GetWebInfo.

No fix yet
Fix from $2,300 2021-04-12
Pega Platform MEDIUM 6.1
CVE-2020-23957

Pega Platform through 8.4.x is affected by Cross Site Scripting (XSS) via the ConnectionID parameter, as demonstrated by a pyActivity=Data-TRACERSett…

Fix: after 8.4.2
Fix from $1,600 2020-12-15
Pega Platform MEDIUM 6.1
CVE-2020-24353

Pega Platform before 8.4.0 has a XSS issue via stream rule parameters used in the request header.

Fix: 8.4+
Fix from $1,600 2020-11-09
Platform CRITICAL 9.8
CVE-2019-16374

Pega Platform 8.2.1 allows LDAP injection because a username can contain a * character and can be of unlimited length. An attacker can specify four c…

Fix: after 8.2.1
Fix from $2,300 2020-08-13
Platform HIGH 8.9
CVE-2020-8775

Pega Platform before version 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the comment tags.

Fix: 8.2.6+
Fix from $1,950 2020-04-29