Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pegasystems Inc.

First CVE: Aug 2, 2017Active for: 9 yearsTotal CVEs: 50
34.7
VTI Score
Medium

Pegasystems Inc. develops a broad enterprise process-automation and customer-engagement platform whose vulnerabilities, despite a narrow product portfolio, reach a prominent position in the vulnerability landscape due to the platform's deployment across critical business workflows. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and a moderate tendency toward public exploit availability. The exposure clusters within the Pega Platform and its related components and recurs through weakness classes including cross-site scripting, direct-request flaws, and improper authentication and authorization controls that are typical of web-facing enterprise application stacks. Defenders should prioritize patching for this vendor given the business-critical nature of affected deployments and the tendency of platform vulnerabilities to enable lateral movement within integrated environments. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
50
Total CVEs
More Total CVEs than 98% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Pegasystems Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 2, 2017
8 years ago
Most Recent CVE
Jul 15, 2026
9 days ago

Self-Reporting Analysis

Of all the CVEs published by Pegasystems Inc. as a CNA, 84.1% affect products that Pegasystems Inc. develops as a vendor.

84.1%
15.9%
Self-reported: 37 (84.1%)
Third-party: 7 (15.9%)

Of all the CVEs published that affect products developed by Pegasystems Inc., 74.0% are self-published by Pegasystems Inc. as a CNA.

74.0%
26.0%
Self-published: 37 (74.0%)
Other CNAs: 13 (26.0%)

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (50 CVEs).

50 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-27651CRITICAL
In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication checks.
Apr 29, 20219.870NOYES
CVE-2022-24082CRITICAL
If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is not properly configured, then it
Jul 19, 20229.850NOYES
CVE-2022-24083CRITICAL
Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks.
Jul 25, 20229.831NONO
CVE-2019-16374CRITICAL
Pega Platform 8.2.1 allows LDAP injection because a username can contain a * character and can be of unlimited length. An attacker can specify four characters of a username, follow
Aug 13, 20209.830NONO
CVE-2020-8773HIGH
The Richtext Editor in Pega Platform before 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability.
Apr 29, 20208.929NONO
CVE-2020-8774HIGH
Pega Platform before version 8.2.6 is affected by a Reflected Cross-Site Scripting vulnerability in the "ActionStringID" function.
Apr 29, 20208.828NONO
CVE-2017-11355MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in PEGA Platform 7.2 ML0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to the
Aug 2, 20176.128NOYES
CVE-2020-8775HIGH
Pega Platform before version 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the comment tags.
Apr 29, 20208.927NONO
CVE-2017-11356MEDIUM
The application distribution export functionality in PEGA Platform 7.2 ML0 and earlier allows remote authenticated users with certain privileges to obtain sensitive configuration i
Aug 2, 20176.527NOYES
CVE-2024-10094CRITICAL
Pega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of Code
Nov 20, 20249.826NONO
View all 50 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products50 CVEs
66%
16%
16%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (4.0%)
Network48 (96.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low49 (98.0%)
High1 (2.0%)
Unknown0 (0.0%)
User Interaction
None21 (42.0%)
Unknown0 (0.0%)
Required29 (58.0%)
Privileges Required
Low13 (26.0%)
High13 (26.0%)
None24 (48.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (50 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
2.0% of CVEs· 95th percentile
ExploitDB
3 CVEs
6.0% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pegasystems Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pegasystems Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pegasystems Inc.'s Products

View all 2 CNAs →

Top CWEs