Vulnerabilities > Pega > Pega Platform > 8.8.3
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-03-14 | CVE-2023-50168 | XXE vulnerability in Pega Platform Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation. | 7.7 |
2024-03-06 | CVE-2023-50167 | Cross-site Scripting vulnerability in Pega Platform Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content. | 6.1 |
2023-09-08 | CVE-2023-4843 | Cross-site Scripting vulnerability in Pega Platform Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Business Director, however this field can only be modified by an authenticated administrative user. | 4.8 |
2023-06-22 | CVE-2023-28094 | Unspecified vulnerability in Pega Platform Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default credentials. | 9.8 |