Vulnerabilities > Pega > Platform

DATE CVE VULNERABILITY TITLE RISK
2024-01-31 CVE-2023-50165 Server-Side Request Forgery (SSRF) vulnerability in Pega Platform
Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents.
network
low complexity
pega CWE-918
8.6
2024-01-31 CVE-2023-50166 Cross-site Scripting vulnerability in Pega Platform
Pega Platform from 8.5.4 to 8.8.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.
network
low complexity
pega CWE-79
6.1
2023-10-18 CVE-2023-32087 Cross-site Scripting vulnerability in Pega Platform
Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with task creation
network
low complexity
pega CWE-79
6.1
2023-10-18 CVE-2023-32088 Cross-site Scripting vulnerability in Pega Platform
Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with ad-hoc case creation
network
low complexity
pega CWE-79
6.1
2023-10-18 CVE-2023-32089 Cross-site Scripting vulnerability in Pega Platform
Pega Platform versions 8.1 to 8.8.2 are affected by an XSS issue with Pin description
network
low complexity
pega CWE-79
6.1
2020-08-13 CVE-2019-16374 Unspecified vulnerability in Pega Platform 8.1.7/8.1.8/8.2.1
Pega Platform 8.2.1 allows LDAP injection because a username can contain a * character and can be of unlimited length.
network
low complexity
pega
7.5
2020-04-29 CVE-2020-8775 Cross-site Scripting vulnerability in Pega Platform
Pega Platform before version 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the comment tags.
network
pega CWE-79
6.0
2020-04-29 CVE-2020-8773 Cross-site Scripting vulnerability in Pega Platform
The Richtext Editor in Pega Platform before 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability.
network
pega CWE-79
6.0