Show filters
19 Total Results
Displaying 1-10 of 19
Sort by:
Attacker Value
Unknown

CVE-2023-50168

Disclosure Date: March 14, 2024 (last updated April 01, 2024)
Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation.
0
Attacker Value
Unknown

CVE-2023-50167

Disclosure Date: March 06, 2024 (last updated February 19, 2025)
Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content.
Attacker Value
Unknown

CVE-2023-4843

Disclosure Date: September 08, 2023 (last updated October 08, 2023)
Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Business Director, however this field can only be modified by an authenticated administrative user.
Attacker Value
Unknown

CVE-2023-32090

Disclosure Date: August 07, 2023 (last updated October 08, 2023)
Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials
Attacker Value
Unknown

CVE-2023-28094

Disclosure Date: June 22, 2023 (last updated October 08, 2023)
Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default credentials.
Attacker Value
Unknown

CVE-2023-26465

Disclosure Date: June 09, 2023 (last updated October 08, 2023)
Pega Platform versions 7.2 to 8.8.1 are affected by an XSS issue.
Attacker Value
Unknown

CVE-2022-35656

Disclosure Date: August 22, 2022 (last updated February 24, 2025)
Pega Platform from 8.3 to 8.7.3 vulnerability may allow authenticated security administrators to alter CSRF settings directly.
Attacker Value
Unknown

CVE-2022-35655

Disclosure Date: August 22, 2022 (last updated February 24, 2025)
Pega Platform from 7.3 to 8.7.3 is affected by an XSS issue due to a misconfiguration of a datapage setting.
Attacker Value
Unknown

CVE-2022-35654

Disclosure Date: August 22, 2022 (last updated February 24, 2025)
Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.
Attacker Value
Unknown

CVE-2020-15390

Disclosure Date: April 12, 2021 (last updated February 22, 2025)
pyActivity in Pega Platform 8.4.0.237 has a security misconfiguration that leads to an improper access control vulnerability via =GetWebInfo.