Vulnerabilities in Pegasystems

46 results
Vexday analysis

Pegasystems acumula 43 vulnerabilidades registradas, com 6 classificadas como críticas, porém nenhuma sob ataque ativo confirmado no momento. A fraqueza dominante é XSS (CWE-79), padrão em plataformas web, e apenas 3 CVEs foram publicadas nos últimos 90 dias, indicando risco não-urgente mas que requer monitoramento de injeção em formulários e outputs.

CVE-2023-50166MEDIUMPega Platform from 8.5.4 to 8.8.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.EPSS 0.3%CVE-2022-35656MEDIUMPega Platform from 8.3 to 8.7.3 vulnerability may allow authenticated security administrators to alter CSRF settings directly.EPSS 0.3%CVE-2026-1078HIGHAn arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robotic Automation version 22.1 or R25 users who are running automations that work with Google Chrome or Microsoft Edge.EPSS 0.3%CVE-2026-0898CRITICALAn arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robot Studio developers who are automating Google Chrome and Microsoft Edge using either version 22.1 or R25.EPSS 0.3%CVE-2024-12211MEDIUMPega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile.EPSS 0.3%CVE-2023-32088MEDIUM Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with ad-hoc case creation EPSS 0.3%CVE-2023-32087MEDIUM Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with task creation EPSS 0.3%CVE-2023-50167MEDIUMPega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content.EPSS 0.3%CVE-2023-32089MEDIUM Pega Platform versions 8.1 to 8.8.2 are affected by an XSS issue with Pin description EPSS 0.3%CVE-2025-2160HIGHPega Platform versions 8.4.3 to Infinity 24.2.1 are affected by an XSS issue with MashupEPSS 0.3%CVE-2025-2161HIGHPega Platform versions 7.2.1 to Infinity 24.2.1 are affected by an XSS issue with MashupEPSS 0.3%CVE-2025-62182MEDIUMPega Customer Service Framework versions 8.7.0 through 25.1.0 are affected by a Unrestricted file upload vulnerability, where a privileged user could potentially upload a malicious file.EPSS 0.3%CVE-2026-1079MEDIUMA native messaging host vulnerability in Pega Browser Extension (PBE) affects users of all versions of Pega Robotic Automation who have installed Pega Browser Extension.EPSS 0.3%CVE-2025-62183MEDIUMPega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to Confidentiality and Integrity are low.EPSS 0.3%CVE-2024-6702MEDIUMPega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage.EPSS 0.3%CVE-2024-6701MEDIUMPega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with case type.EPSS 0.3%CVE-2024-6700MEDIUMPega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with App name.EPSS 0.3%CVE-2025-62184MEDIUMPega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interface component.EPSS 0.3%CVE-2026-13761HIGHPega Platform versions 7.1.0 through 25.1.2 are affected by an improper validation of inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping.EPSS 0.3%CVE-2026-1563MEDIUMPega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.EPSS 0.2%