SecAlerts
pega logo

pega

Security Risk Profile

31
/100
low

Security Risk Score

Comprehensive risk assessment based on 55 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from August 2, 2017 to present

55
Total CVEs
22
Critical+High
0
Exploited
22
Unpatched

Threat Assessment

Avg CVSS
6.8
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
22
Critical/High
Risk Level
31/100
low
🆕 1Fresh (<7d)📈 3 in Last 30 Days

Severity Distribution

Critical
8
High
14
Medium
33
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
4

Age Distribution

Common Weaknesses (CWE)

1
XSS
30
2
Malicious File Upload
1
3
Code Injection
1
4
XEE
1
5
SSRF
1

Most Affected Products

1. Pega Pega Platform63
2. Pega Infinity13
3. Pega Platform12
4. PEGA Infinity8
5. Pegasystems Pega Platform3

Recent Vulnerabilities

See more →
CVE-2026-14337
CVSS 4.6medium

Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.

8/4/2026🔧 No Patch
CVE-2026-1563
CVSS 4.8medium

Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.

7/15/2026🔧 No Patch
CVE-2026-1562
CVSS 4.6medium

Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.

7/15/2026🔧 No Patch
CVE-2026-1711
CVSS 4.8medium

Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerability in a user interface component. Requires a high privileged user with a developer role.

4/15/2026🔧 No Patch
CVE-2026-1564
CVSS 5.1medium

Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface component. Requires a high privileged user with a developer role.

4/15/2026🔧 No Patch
CVE-2026-1078
CVSS 7.2high

An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robotic Automation version 22.1 or R25 users who are running automations that work with Google Chrome or Microsoft Edge.

4/7/2026🔧 No Patch
CVE-2025-62184
CVSS 4.8medium

Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interface component.

3/31/2026🔧 No Patch
CVE-2025-62183
CVSS 4.8medium

Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to Confidentiality and Integrity are low.

2/17/2026🔧 No Patch
CVE-2025-62182
CVSS 5.3medium

Pega Customer Service Framework versions 8.7.0 through 25.1.0 are affected by a Unrestricted file upload vulnerability, where a privileged user could potentially upload a malicious file.

1/13/2026🔧 No Patch
CVE-2025-62181
CVSS 5.3medium

Pega Platform versions 7.1.0 through Infinity 25.1.0 are affected by a User Enumeration where during user authentication process, a difference in response time could allow a remote unauthenticated user to determine if a username is valid or not.

12/10/2025🔧 No Patch

Monitor pega in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.