Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
pega pega platform vulnerabilities and exploits
(subscribe to this query)
4.8
CVSSv3
CVE-2017-17478
An XSS issue exists in Designer Studio in Pegasystems Pega Platform 7.1.7, 7.1.8, 7.1.9, 7.1.10, 7.2, 7.2.1, and 7.2.2. A user with developer credentials can insert malicious code (up to 64 characters) into a text field in Designer Studio, after establishing context. Designer Stu...
Pega Pega Platform 7.2.1
Pega Pega Platform 7.2.2
Pega Pega Platform 7.1.7
Pega Pega Platform 7.1.9
Pega Pega Platform 7.2
Pega Pega Platform 7.1.8
Pega Pega Platform 7.1.10
6.1
CVSSv3
CVE-2023-26465
Pega Platform versions 7.2 to 8.8.1 are affected by an XSS issue.
Pega Pega Platform
8.8
CVSSv3
CVE-2020-8774
Pega Platform before version 8.2.6 is affected by a Reflected Cross-Site Scripting vulnerability in the "ActionStringID" function.
Pega Pega Platform
4.3
CVSSv3
CVE-2019-16386
PEGA Platform 7.x and 8.x is vulnerable to Information disclosure via a direct prweb/sso/random_token/!STANDARD?pyActivity=GetWebInfo&target=popup&pzHarnessID=random_harness_id request to get database schema information while using a low-privilege account. NOTE: The vendo...
Pega Pega Platform
6.5
CVSSv3
CVE-2017-11356
The application distribution export functionality in PEGA Platform 7.2 ML0 and previous versions allows remote authenticated users with certain privileges to obtain sensitive configuration information by leveraging a missing access control.
Pega Pega Platform
1 EDB exploit
6.1
CVSSv3
CVE-2022-35654
Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.
Pega Pega Platform
6.1
CVSSv3
CVE-2022-35655
Pega Platform from 7.3 to 8.7.3 is affected by an XSS issue due to a misconfiguration of a datapage setting.
Pega Pega Platform
4.5
CVSSv3
CVE-2022-35656
Pega Platform from 8.3 to 8.7.3 vulnerability may allow authenticated security administrators to alter CSRF settings directly.
Pega Pega Platform
9.8
CVSSv3
CVE-2023-28094
Pega platform clients who are using versions 7.4 up to and including 8.8.x and have upgraded from a version before 8.x may be utilizing default credentials.
Pega Pega Platform
6.1
CVSSv3
CVE-2020-23957
Pega Platform up to and including 8.4.x is affected by Cross Site Scripting (XSS) via the ConnectionID parameter, as demonstrated by a pyActivity=Data-TRACERSettings.pzStartTracerSession request to a PRAuth URI.
Pega Pega Platform
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-7073
CVE-2024-5496
CVE-2024-5495
XPath injection
bypass
CVE-2024-30043
CVE-2024-24919
denial of service
CVE-2024-35468
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »