Pega Platform

Vendor:

First CVE: Aug 2, 2017 · Active for 8 years

34
Total CVEs
More Total CVEs than 96% of tracked products
3.4
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 25% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Pega Platform over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 2, 2017
8 years ago
Most Recent CVE
Jul 15, 2026
10 days ago

CVE Severity & Scoring

Pega Platform34 CVEs
All CVEs352,708 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network34 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low34 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (32.4%)
Unknown0 (0.0%)
Required23 (67.6%)
Privileges Required
Low8 (23.5%)
High8 (23.5%)
None18 (52.9%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (34 CVEs).

34 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Pega Platform before version 8.2.6 is affected by a Reflected Cross-Site Scripting vulnerability in the "ActionStringID" function.
Apr 29, 20208.828NONO
Multiple cross-site scripting (XSS) vulnerabilities in PEGA Platform 7.2 ML0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to the
Aug 2, 20176.128NOYES
The application distribution export functionality in PEGA Platform 7.2 ML0 and earlier allows remote authenticated users with certain privileges to obtain sensitive configuration i
Aug 2, 20176.527NOYES
Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials
Aug 7, 20239.826NONO
Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default credentials.
Jun 22, 20239.826NONO
Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user wit
Jul 15, 20264.824NONO
Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a
Jul 15, 20264.824NONO
pyActivity in Pega Platform 8.4.0.237 has a security misconfiguration that leads to an improper access control vulnerability via =GetWebInfo.
Apr 12, 20219.824NONO
Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user interface component that can only be used to read data.
Oct 16, 20256.523NONO
PEGA Platform 8.3.0 is vulnerable to a direct prweb/sso/random_token/!STANDARD?pyActivity=Data-Admin-DB-Name.DBSchema_ListDatabases request while using a low-privilege account. (Th
Nov 26, 20198.123NONO

Exploit Exposure

Signals from CVEs in this product scope (34 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
5.9% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (34 CVEs).

Media Mentions

Signals from CVEs in this product scope (34 CVEs).

Top CNAs Publishing CVEs For Pega Platform

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.4.0.23719.81.4%00
8.326.20.9%00
7.2.214.80.5%00
7.2.114.80.5%00
7.214.80.5%00
7.1.914.80.5%00
7.1.814.80.5%00
7.1.714.80.5%00
7.1.1014.80.5%00
24.2.035.90.3%00
23.1.116.10.3%00