« Volver al listado

Pega

Pega Platform: vulnerabilidades y CVE

Pega Platform tiene 35 vulnerabilidades publicadas, 12 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE35
Últimos 12 meses12
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-13761Alta (8.8)0.25%—28 ago 2026
Pega Platform versions 7.1.0 through 25.1.2 are affected by an improper validation of inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive…
CVE-2026-10754Alta (8.6)0.78%—10 ago 2026
Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may allow an attacker to bypass security controls.
CVE-2026-14337Media (4.6)0.42%—4 ago 2026
Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
CVE-2026-1563Media (4.8)0.24%—15 jul 2026
Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
CVE-2026-1562Media (4.6)0.24%—15 jul 2026
Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
CVE-2025-62180Alta (7.1)0.36%—23 jun 2026
Pega Platform versions 8.3.0 through Infinity 25.1.2 are affected by an authorization weakness that may allow authenticated users to access certain additional data via crafted URLs.
CVE-2026-1711Media (4.8)0.19%—15 abr 2026
Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerability in a user interface component. Requires a high privileged user with a developer role.
CVE-2026-1564Media (5.1)0.19%—15 abr 2026
Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface component. Requires a high privileged user with a developer role.
CVE-2025-62184Media (4.8)0.26%—31 mar 2026
Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to…
CVE-2025-62183Media (4.8)0.26%—17 feb 2026
Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to…
CVE-2025-62181Media (5.3)0.44%—10 dic 2025
Pega Platform versions 7.1.0 through Infinity 25.1.0 are affected by a User Enumeration. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated…
CVE-2025-9559Media (6.5)0.40%—16 oct 2025
Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user interface component that can only be used to read data.
CVE-2025-8681Media (5.4)0.19%—10 sept 2025
Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component. Requires a high privileged user with a developer role.
CVE-2025-2161Media (6.1)0.28%—14 abr 2025
Pega Platform versions 7.2.1 to Infinity 24.2.1 are affected by an XSS issue with Mashup
CVE-2025-2160Media (6.1)0.28%—14 abr 2025
Pega Platform versions 8.4.3 to Infinity 24.2.1 are affected by an XSS issue with Mashup
CVE-2024-12211Media (5.4)0.32%—13 ene 2025
Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile.
CVE-2023-50168Alta (7.7)0.39%—14 mar 2024
Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation.
CVE-2023-50167Media (6.1)0.30%—6 mar 2024
Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content.
CVE-2023-4843Media (4.8)0.34%—8 sept 2023
Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Business Director, however this field can only be modified by an authenticated administrative user.
CVE-2023-32090Crítica (9.8)0.62%—7 ago 2023
Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials
CVE-2023-28094Crítica (9.8)0.53%—22 jun 2023
Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default credentials.
CVE-2023-26465Media (6.1)0.44%—9 jun 2023
Pega Platform versions 7.2 to 8.8.1 are affected by an XSS issue.
CVE-2022-35656Media (4.5)0.33%—22 ago 2022
Pega Platform from 8.3 to 8.7.3 vulnerability may allow authenticated security administrators to alter CSRF settings directly.
CVE-2022-35655Media (6.1)0.47%—22 ago 2022
Pega Platform from 7.3 to 8.7.3 is affected by an XSS issue due to a misconfiguration of a datapage setting.
CVE-2022-35654Media (6.1)0.52%—22 ago 2022
Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.
CVE-2020-15390Crítica (9.8)1.3%—12 abr 2021
pyActivity in Pega Platform 8.4.0.237 has a security misconfiguration that leads to an improper access control vulnerability via =GetWebInfo.
CVE-2020-23957Media (6.1)0.69%—15 dic 2020
Pega Platform through 8.4.x is affected by Cross Site Scripting (XSS) via the ConnectionID parameter, as demonstrated by a pyActivity=Data-TRACERSettings.pzStartTracerSession request to a PRAuth URI.
CVE-2020-24353Media (6.1)0.65%—9 nov 2020
Pega Platform before 8.4.0 has a XSS issue via stream rule parameters used in the request header.
CVE-2020-8774Alta (8.8)0.83%—29 abr 2020
Pega Platform before version 8.2.6 is affected by a Reflected Cross-Site Scripting vulnerability in the "ActionStringID" function.
CVE-2019-16388Media (4.3)0.71%—26 nov 2019
PEGA Platform 8.3.0 is vulnerable to Information disclosure via a direct prweb/sso/random_token/!STANDARD?pyStream=MyAlerts request to get Audit Log information while using a low-privilege account. NOTE: The vendor…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services2
  2. T1005 Data from Local System1
  3. T1190 Exploit Public-Facing Application1
  4. T1553 Subvert Trust Controls1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Pega