Pega
Pega Platform: vulnerabilities and CVEs
Pega Platform has 35 published vulnerabilities, 12 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.
CVEs35
Last 12 months12
Critical3
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-13761 | High (8.8) | 0.25% | — | Aug 28, 2026 | Pega Platform versions 7.1.0 through 25.1.2 are affected by an improper validation of inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive… |
| CVE-2026-10754 | High (8.6) | 0.78% | — | Aug 10, 2026 | Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may allow an attacker to bypass security controls. |
| CVE-2026-14337 | Medium (4.6) | 0.42% | — | Aug 4, 2026 | Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role. |
| CVE-2026-1563 | Medium (4.8) | 0.24% | — | Jul 15, 2026 | Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role. |
| CVE-2026-1562 | Medium (4.6) | 0.24% | — | Jul 15, 2026 | Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role. |
| CVE-2025-62180 | High (7.1) | 0.36% | — | Jun 23, 2026 | Pega Platform versions 8.3.0 through Infinity 25.1.2 are affected by an authorization weakness that may allow authenticated users to access certain additional data via crafted URLs. |
| CVE-2026-1711 | Medium (4.8) | 0.19% | — | Apr 15, 2026 | Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerability in a user interface component. Requires a high privileged user with a developer role. |
| CVE-2026-1564 | Medium (5.1) | 0.19% | — | Apr 15, 2026 | Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface component. Requires a high privileged user with a developer role. |
| CVE-2025-62184 | Medium (4.8) | 0.26% | — | Mar 31, 2026 | Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to… |
| CVE-2025-62183 | Medium (4.8) | 0.26% | — | Feb 17, 2026 | Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to… |
| CVE-2025-62181 | Medium (5.3) | 0.44% | — | Dec 10, 2025 | Pega Platform versions 7.1.0 through Infinity 25.1.0 are affected by a User Enumeration. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated… |
| CVE-2025-9559 | Medium (6.5) | 0.40% | — | Oct 16, 2025 | Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user interface component that can only be used to read data. |
| CVE-2025-8681 | Medium (5.4) | 0.19% | — | Sep 10, 2025 | Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component. Requires a high privileged user with a developer role. |
| CVE-2025-2161 | Medium (6.1) | 0.28% | — | Apr 14, 2025 | Pega Platform versions 7.2.1 to Infinity 24.2.1 are affected by an XSS issue with Mashup |
| CVE-2025-2160 | Medium (6.1) | 0.28% | — | Apr 14, 2025 | Pega Platform versions 8.4.3 to Infinity 24.2.1 are affected by an XSS issue with Mashup |
| CVE-2024-12211 | Medium (5.4) | 0.32% | — | Jan 13, 2025 | Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile. |
| CVE-2023-50168 | High (7.7) | 0.39% | — | Mar 14, 2024 | Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation. |
| CVE-2023-50167 | Medium (6.1) | 0.30% | — | Mar 6, 2024 | Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content. |
| CVE-2023-4843 | Medium (4.8) | 0.34% | — | Sep 8, 2023 | Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Business Director, however this field can only be modified by an authenticated administrative user. |
| CVE-2023-32090 | Critical (9.8) | 0.62% | — | Aug 7, 2023 | Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials |
| CVE-2023-28094 | Critical (9.8) | 0.53% | — | Jun 22, 2023 | Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default credentials. |
| CVE-2023-26465 | Medium (6.1) | 0.44% | — | Jun 9, 2023 | Pega Platform versions 7.2 to 8.8.1 are affected by an XSS issue. |
| CVE-2022-35656 | Medium (4.5) | 0.33% | — | Aug 22, 2022 | Pega Platform from 8.3 to 8.7.3 vulnerability may allow authenticated security administrators to alter CSRF settings directly. |
| CVE-2022-35655 | Medium (6.1) | 0.47% | — | Aug 22, 2022 | Pega Platform from 7.3 to 8.7.3 is affected by an XSS issue due to a misconfiguration of a datapage setting. |
| CVE-2022-35654 | Medium (6.1) | 0.52% | — | Aug 22, 2022 | Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter. |
| CVE-2020-15390 | Critical (9.8) | 1.3% | — | Apr 12, 2021 | pyActivity in Pega Platform 8.4.0.237 has a security misconfiguration that leads to an improper access control vulnerability via =GetWebInfo. |
| CVE-2020-23957 | Medium (6.1) | 0.69% | — | Dec 15, 2020 | Pega Platform through 8.4.x is affected by Cross Site Scripting (XSS) via the ConnectionID parameter, as demonstrated by a pyActivity=Data-TRACERSettings.pzStartTracerSession request to a PRAuth URI. |
| CVE-2020-24353 | Medium (6.1) | 0.65% | — | Nov 9, 2020 | Pega Platform before 8.4.0 has a XSS issue via stream rule parameters used in the request header. |
| CVE-2020-8774 | High (8.8) | 0.83% | — | Apr 29, 2020 | Pega Platform before version 8.2.6 is affected by a Reflected Cross-Site Scripting vulnerability in the "ActionStringID" function. |
| CVE-2019-16388 | Medium (4.3) | 0.71% | — | Nov 26, 2019 | PEGA Platform 8.3.0 is vulnerable to Information disclosure via a direct prweb/sso/random_token/!STANDARD?pyStream=MyAlerts request to get Audit Log information while using a low-privilege account. NOTE: The vendor… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.