Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
pega platform vulnerabilities and exploits
(subscribe to this query)
312
VMScore
CVE-2017-17478
An XSS issue exists in Designer Studio in Pegasystems Pega Platform 7.1.7, 7.1.8, 7.1.9, 7.1.10, 7.2, 7.2.1, and 7.2.2. A user with developer credentials can insert malicious code (up to 64 characters) into a text field in Designer Studio, after establishing context. Designer Stu...
Pega Pega Platform 7.2.1
Pega Pega Platform 7.2.2
Pega Pega Platform 7.1.7
Pega Pega Platform 7.1.9
Pega Pega Platform 7.2
Pega Pega Platform 7.1.8
Pega Pega Platform 7.1.10
NA
CVE-2023-32090
Pega platform clients who are using versions 6.1 up to and including 7.3.1 may be utilizing default credentials
Pega Pega Platform
NA
CVE-2022-35654
Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.
Pega Pega Platform
NA
CVE-2023-26465
Pega Platform versions 7.2 to 8.8.1 are affected by an XSS issue.
Pega Pega Platform
NA
CVE-2023-4843
Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Business Director, however this field can only be modified by an authenticated administrative user.
Pega Pega Platform
605
VMScore
CVE-2020-8774
Pega Platform before version 8.2.6 is affected by a Reflected Cross-Site Scripting vulnerability in the "ActionStringID" function.
Pega Pega Platform
NA
CVE-2023-28094
Pega platform clients who are using versions 7.4 up to and including 8.8.x and have upgraded from a version before 8.x may be utilizing default credentials.
Pega Pega Platform
NA
CVE-2022-35655
Pega Platform from 7.3 to 8.7.3 is affected by an XSS issue due to a misconfiguration of a datapage setting.
Pega Pega Platform
NA
CVE-2022-35656
Pega Platform from 8.3 to 8.7.3 vulnerability may allow authenticated security administrators to alter CSRF settings directly.
Pega Pega Platform
435
VMScore
CVE-2017-11355
Multiple cross-site scripting (XSS) vulnerabilities in PEGA Platform 7.2 ML0 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the (1) PATH_INFO to the main page; the (2) beanReference parameter to the JavaBean viewer page; or the (3) p...
Pega Pega Platform
1 EDB exploit
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
camera
bypass
CVE-2024-3592
CVE-2024-37383
CVE-2024-24919
CVE-2024-27822
CVE-2024-36788
CVE-2024-36789
man-in-the-middle
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »