pega
Enterprise Softwarecommercial
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting pega.
- CVE-2026-1563Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.4.8
- CVE-2026-1562Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.4.8
- CVE-2026-1711Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerability in a user interface component. Requires a high privileged user with a developer role.4.8
- CVE-2026-1564Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface component. Requires a high privileged user with a developer role.4.8
- CVE-2025-62184Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interface component.3.4
- CVE-2025-9559Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user interface component that can only be used to read data6.5
- CVE-2025-8681Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component5.5
- CVE-2025-2161Pega Platform versions 7.2.1 to Infinity 24.2.1 are affected by an XSS issue with Mashup7.1
- CVE-2025-2160Pega Platform versions 8.4.3 to Infinity 24.2.1 are affected by an XSS issue with Mashup8.1
- CVE-2024-12211Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile.5.4
- CVE-2024-10716Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search.5.9
- CVE-2024-10094Pega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of Code9.1
- CVE-2024-6702Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage.5.2
- CVE-2024-6701Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with case type.5.5
- CVE-2024-6700Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with App name.5.5