CVE-2026-10754
- EPSS 0.57%
- Veröffentlicht 10.08.2026 17:38:01
- Zuletzt bearbeitet 11.08.2026 16:17:26
Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may allow an attacker to bypass security controls.
CVE-2026-14337
- EPSS 0.25%
- Veröffentlicht 04.08.2026 13:48:40
- Zuletzt bearbeitet 04.08.2026 19:16:42
Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
CVE-2026-1563
- EPSS 0.17%
- Veröffentlicht 15.07.2026 16:38:21
- Zuletzt bearbeitet 21.07.2026 16:54:21
Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
CVE-2026-1562
- EPSS 0.17%
- Veröffentlicht 15.07.2026 16:37:13
- Zuletzt bearbeitet 21.07.2026 16:55:39
Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
CVE-2025-62180
- EPSS 0.22%
- Veröffentlicht 23.06.2026 14:48:36
- Zuletzt bearbeitet 23.06.2026 19:34:58
Pega Platform versions 8.3.0 through Infinity 25.1.2 are affected by an authorization weakness that may allow authenticated users to access certain additional data via crafted URLs.
CVE-2026-1711
- EPSS 0.19%
- Veröffentlicht 15.04.2026 21:32:51
- Zuletzt bearbeitet 23.04.2026 20:01:09
Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerability in a user interface component. Requires a high privileged user with a developer role.
CVE-2026-1564
- EPSS 0.19%
- Veröffentlicht 15.04.2026 21:31:19
- Zuletzt bearbeitet 23.04.2026 20:02:20
Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface component. Requires a high privileged user with a developer role.
CVE-2025-62184
- EPSS 0.26%
- Veröffentlicht 31.03.2026 17:52:07
- Zuletzt bearbeitet 24.07.2026 20:10:00
Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to Confidentiality is low and Integrity ...
CVE-2025-62183
- EPSS 0.25%
- Veröffentlicht 17.02.2026 22:53:22
- Zuletzt bearbeitet 15.04.2026 00:35:42
Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to Confidentiality and Integrity are low...
CVE-2025-62181
- EPSS 0.45%
- Veröffentlicht 10.12.2025 20:41:08
- Zuletzt bearbeitet 15.04.2026 00:35:42
Pega Platform versions 7.1.0 through Infinity 25.1.0 are affected by a User Enumeration. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated user to determine if a username i...