Pegasystems Inc. develops a broad enterprise process-automation and customer-engagement platform whose vulnerabilities, despite a narrow product portfolio, reach a prominent position in the vulnerability landscape due to the platform's deployment across critical business workflows. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and a moderate tendency toward public exploit availability. The exposure clusters within the Pega Platform and its related components and recurs through weakness classes including cross-site scripting, direct-request flaws, and improper authentication and authorization controls that are typical of web-facing enterprise application stacks. Defenders should prioritize patching for this vendor given the business-critical nature of affected deployments and the tendency of platform vulnerabilities to enable lateral movement within integrated environments. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pegasystems Inc. over time
Of all the CVEs published by Pegasystems Inc. as a CNA, 84.1% affect products that Pegasystems Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Pegasystems Inc., 74.0% are self-published by Pegasystems Inc. as a CNA.
Signals from CVEs in this vendor scope (50 CVEs).
50 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-27651CRITICAL In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication checks. | Apr 29, 2021 | 9.8 | 70 | NO | YES |
CVE-2022-24082CRITICAL If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is not properly configured, then it | Jul 19, 2022 | 9.8 | 50 | NO | YES |
CVE-2022-24083CRITICAL Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks. | Jul 25, 2022 | 9.8 | 31 | NO | NO |
CVE-2019-16374CRITICAL Pega Platform 8.2.1 allows LDAP injection because a username can contain a * character and can be of unlimited length. An attacker can specify four characters of a username, follow | Aug 13, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-8773HIGH The Richtext Editor in Pega Platform before 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability. | Apr 29, 2020 | 8.9 | 29 | NO | NO |
CVE-2020-8774HIGH Pega Platform before version 8.2.6 is affected by a Reflected Cross-Site Scripting vulnerability in the "ActionStringID" function. | Apr 29, 2020 | 8.8 | 28 | NO | NO |
CVE-2017-11355MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in PEGA Platform 7.2 ML0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to the | Aug 2, 2017 | 6.1 | 28 | NO | YES |
CVE-2020-8775HIGH Pega Platform before version 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the comment tags. | Apr 29, 2020 | 8.9 | 27 | NO | NO |
CVE-2017-11356MEDIUM The application distribution export functionality in PEGA Platform 7.2 ML0 and earlier allows remote authenticated users with certain privileges to obtain sensitive configuration i | Aug 2, 2017 | 6.5 | 27 | NO | YES |
CVE-2024-10094CRITICAL Pega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of Code | Nov 20, 2024 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (50 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pegasystems Inc..
Media articles that mention a CVE ID that affects a product developed by Pegasystems Inc. — matched by CVE ID, not by vendor name.