Loading HuntDB...

Vulnerabilities

CVE-2024-12211

MEDIUM

Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile.

Published Jan 13, 2025

CVE-2024-10716

MEDIUM

Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search.

Published Dec 05, 2024

CVE-2024-10094

CRITICAL

Pega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of Code

Published Nov 20, 2024

CVE-2024-6702

MEDIUM

Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage.

Published Sep 12, 2024

CVE-2024-6701

MEDIUM

Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with case type.

Published Sep 12, 2024

CVE-2024-6700

MEDIUM

Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with App name.

Published Sep 12, 2024

CVE-2023-50168

HIGH

Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation.

Published Mar 14, 2024

CVE-2023-50167

MEDIUM

Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content.

Published Mar 06, 2024

CVE-2023-50166

MEDIUM

Pega Platform from 8.5.4 to 8.8.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.

Published Jan 31, 2024

CVE-2023-50165

HIGH

Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents.

Published Jan 31, 2024

CVE-2023-32089

MEDIUM

Pega Platform versions 8.1 to 8.8.2 are affected by an XSS issue with Pin description

Published Oct 18, 2023

CVE-2023-32088

MEDIUM

Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with ad-hoc case creation

Published Oct 18, 2023

CVE-2023-32087

MEDIUM

Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with task creation

Published Oct 18, 2023

CVE-2023-4843

MEDIUM

Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Business Director, however this field can only be modified by an authenticated administrative user.

Published Sep 08, 2023

CVE-2023-32090

CRITICAL

Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials

Published Aug 07, 2023

CVE-2023-28094

HIGH

Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default credentials.

Published Jun 22, 2023

CVE-2023-26465

HIGH

Pega Platform versions 7.2 to 8.8.1 are affected by an XSS issue.

Published Jun 09, 2023

CVE-2023-26466

HIGH

A user with non-Admin access can change a configuration file on the client to modify the Server URL.

Published Apr 10, 2023

CVE-2023-28093

HIGH

A user with a compromised configuration can start an unsigned binary as a service.

Published Apr 10, 2023

CVE-2023-26467

HIGH

A man in the middle can redirect traffic to a malicious server in a compromised configuration.

Published Apr 10, 2023

CVE-2022-35656

MEDIUM

Pega Platform from 8.3 to 8.7.3 vulnerability may allow authenticated security administrators to alter CSRF settings directly.

Published Aug 22, 2022

CVE-2022-35655

MEDIUM

Pega Platform from 7.3 to 8.7.3 is affected by an XSS issue due to a misconfiguration of a datapage setting.

Published Aug 22, 2022

CVE-2022-35654

MEDIUM

Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.

Published Aug 22, 2022

CVE-2022-24083

CRITICAL

Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks.

Published Jul 25, 2022

CVE-2022-24082

CRITICAL

If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is not properly configured, then it may be possible to upload serialized payloads to attack the underlying system. This does not affect systems running on PegaCloud due to its design and architecture.

Published Jul 19, 2022

CVE-2021-27654

HIGH

Forgotten password reset functionality for local accounts can be used to bypass local authentication checks.

Published Jan 28, 2022

CVE-2021-27651

CRITICAL

In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication checks.

Published Apr 29, 2021