CVE-2025-8681: Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component
Published Sep 10, 2025
·Updated
Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component. Requires a high privileged user with a developer role.
Affected Software
4 affected components
Pega Pega Platform>=7.1.0<=24.2.2
Pega Pega Platform>=7.1.0<23.1.5
Pega Pega Platform>=24.1.0<24.1.3
Pega Pega Platform>=24.2.0<24.2.2
Event History
Sep 10, 2025
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-8681?
CVE-2025-8681 has a high severity rating due to the potential for Stored XSS attacks by privileged users.
2
How do I fix CVE-2025-8681?
To fix CVE-2025-8681, update Pega Platform to the latest version that addresses this stored XSS vulnerability.
3
What versions of Pega Platform are affected by CVE-2025-8681?
CVE-2025-8681 affects Pega Platform versions 7.1.0 to 24.2.2.
4
Who is at risk from CVE-2025-8681?
Users with high privileges and developer roles are particularly at risk from CVE-2025-8681.
5
What type of vulnerability is CVE-2025-8681?
CVE-2025-8681 is classified as a Stored XSS vulnerability.