Vulnerabilities > Pega > Pega Platform > 8.4.2
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-09-08 | CVE-2023-4843 | Cross-site Scripting vulnerability in Pega Platform Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Business Director, however this field can only be modified by an authenticated administrative user. | 4.8 |
2023-06-22 | CVE-2023-28094 | Unspecified vulnerability in Pega Platform Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default credentials. | 9.8 |
2023-06-09 | CVE-2023-26465 | Cross-site Scripting vulnerability in Pega Platform Pega Platform versions 7.2 to 8.8.1 are affected by an XSS issue. | 6.1 |
2020-12-15 | CVE-2020-23957 | Cross-site Scripting vulnerability in Pega Platform 8.4/8.4.1/8.4.2 Pega Platform through 8.4.x is affected by Cross Site Scripting (XSS) via the ConnectionID parameter, as demonstrated by a pyActivity=Data-TRACERSettings.pzStartTracerSession request to a PRAuth URI. | 4.3 |