« Back to list

Pega

Pega Platform: vulnerabilities and CVEs

Pega Platform has 35 published vulnerabilities, 12 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.

CVEs35
Last 12 months12
Critical3
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-13761High (8.8)0.25%—Aug 28, 2026
Pega Platform versions 7.1.0 through 25.1.2 are affected by an improper validation of inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive…
CVE-2026-10754High (8.6)0.78%—Aug 10, 2026
Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may allow an attacker to bypass security controls.
CVE-2026-14337Medium (4.6)0.42%—Aug 4, 2026
Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
CVE-2026-1563Medium (4.8)0.24%—Jul 15, 2026
Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
CVE-2026-1562Medium (4.6)0.24%—Jul 15, 2026
Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
CVE-2025-62180High (7.1)0.36%—Jun 23, 2026
Pega Platform versions 8.3.0 through Infinity 25.1.2 are affected by an authorization weakness that may allow authenticated users to access certain additional data via crafted URLs.
CVE-2026-1711Medium (4.8)0.19%—Apr 15, 2026
Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerability in a user interface component. Requires a high privileged user with a developer role.
CVE-2026-1564Medium (5.1)0.19%—Apr 15, 2026
Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface component. Requires a high privileged user with a developer role.
CVE-2025-62184Medium (4.8)0.26%—Mar 31, 2026
Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to…
CVE-2025-62183Medium (4.8)0.26%—Feb 17, 2026
Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to…
CVE-2025-62181Medium (5.3)0.44%—Dec 10, 2025
Pega Platform versions 7.1.0 through Infinity 25.1.0 are affected by a User Enumeration. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated…
CVE-2025-9559Medium (6.5)0.40%—Oct 16, 2025
Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user interface component that can only be used to read data.
CVE-2025-8681Medium (5.4)0.19%—Sep 10, 2025
Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component. Requires a high privileged user with a developer role.
CVE-2025-2161Medium (6.1)0.28%—Apr 14, 2025
Pega Platform versions 7.2.1 to Infinity 24.2.1 are affected by an XSS issue with Mashup
CVE-2025-2160Medium (6.1)0.28%—Apr 14, 2025
Pega Platform versions 8.4.3 to Infinity 24.2.1 are affected by an XSS issue with Mashup
CVE-2024-12211Medium (5.4)0.32%—Jan 13, 2025
Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile.
CVE-2023-50168High (7.7)0.39%—Mar 14, 2024
Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation.
CVE-2023-50167Medium (6.1)0.30%—Mar 6, 2024
Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content.
CVE-2023-4843Medium (4.8)0.34%—Sep 8, 2023
Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Business Director, however this field can only be modified by an authenticated administrative user.
CVE-2023-32090Critical (9.8)0.62%—Aug 7, 2023
Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials
CVE-2023-28094Critical (9.8)0.53%—Jun 22, 2023
Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default credentials.
CVE-2023-26465Medium (6.1)0.44%—Jun 9, 2023
Pega Platform versions 7.2 to 8.8.1 are affected by an XSS issue.
CVE-2022-35656Medium (4.5)0.33%—Aug 22, 2022
Pega Platform from 8.3 to 8.7.3 vulnerability may allow authenticated security administrators to alter CSRF settings directly.
CVE-2022-35655Medium (6.1)0.47%—Aug 22, 2022
Pega Platform from 7.3 to 8.7.3 is affected by an XSS issue due to a misconfiguration of a datapage setting.
CVE-2022-35654Medium (6.1)0.52%—Aug 22, 2022
Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.
CVE-2020-15390Critical (9.8)1.3%—Apr 12, 2021
pyActivity in Pega Platform 8.4.0.237 has a security misconfiguration that leads to an improper access control vulnerability via =GetWebInfo.
CVE-2020-23957Medium (6.1)0.69%—Dec 15, 2020
Pega Platform through 8.4.x is affected by Cross Site Scripting (XSS) via the ConnectionID parameter, as demonstrated by a pyActivity=Data-TRACERSettings.pzStartTracerSession request to a PRAuth URI.
CVE-2020-24353Medium (6.1)0.65%—Nov 9, 2020
Pega Platform before 8.4.0 has a XSS issue via stream rule parameters used in the request header.
CVE-2020-8774High (8.8)0.83%—Apr 29, 2020
Pega Platform before version 8.2.6 is affected by a Reflected Cross-Site Scripting vulnerability in the "ActionStringID" function.
CVE-2019-16388Medium (4.3)0.71%—Nov 26, 2019
PEGA Platform 8.3.0 is vulnerable to Information disclosure via a direct prweb/sso/random_token/!STANDARD?pyStream=MyAlerts request to get Audit Log information while using a low-privilege account. NOTE: The vendor…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1210 Exploitation of Remote Services2
  2. T1005 Data from Local System1
  3. T1190 Exploit Public-Facing Application1
  4. T1553 Subvert Trust Controls1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Pega