Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Pega Infinity — Vulnerabilities & Security Advisories 31

All 31 CVE vulnerabilities found in Pega Infinity, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerabilities for Pega Infinity, a workflow automation product, categorized by specific weakness types and security tags. It collects disclosed security flaws affecting the platform, covering advisories published within the past five years. Here you can track the vendor’s security bulletins, analyze a particular weakness class, or review the product’s vulnerability history. The collection provides a structured view of known issues, enabling security teams to assess exposure and prioritize remediation efforts. Each entry links to the original advisory, offering context on impact and affected versions. The data is curated from trusted public sources and updated regularly to reflect the latest disclosures. This resource serves as a reference for risk assessment, penetration testing planning, and compliance auditing. No specific CVE identifiers are listed here; instead, the focus remains on pattern recognition and trend analysis. Users can filter by year, severity, or vulnerability category to narrow the dataset. The goal is to provide clarity on the threat landscape without marketing language or promotional content.

Vendor: Pegasystems

CVE ID Title CVSS Severity Published
CVE-2026-13761 Pega Platform versions 7.1.0 through 25.1.2 are affected by an improper validation of inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping. CWE-606 8.8 High 2026-08-28
CVE-2026-10754 Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may allow an attacker to bypass security controls. CWE-347 8.6 High 2026-08-10
CVE-2026-14337 Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role. CWE-79 4.6 Medium 2026-08-04
CVE-2026-1563 Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role. CWE-79 - - 2026-07-15
CVE-2026-1562 Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role. CWE-79 - - 2026-07-15
CVE-2025-62180 Pega Platform versions 8.3.0 through Infinity 25.1.2 are affected by an authorization weakness that may allow authenticated users to access certain additional data via crafted URLs. CWE-639 - - 2026-06-23
CVE-2026-1711 Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerability in a user interface component. Requires a high privileged user with a developer role. CWE-79 4.8 - 2026-04-15
CVE-2026-1564 Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface component. Requires a high privileged user with a developer role. CWE-80 5.5 - 2026-04-15
CVE-2025-62184 Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. CWE-79 4.8AI Medium AI 2026-03-31
CVE-2025-62183 Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to Confidentiality and Integrity are low. CWE-79 4.8AI Medium AI 2026-02-17
CVE-2025-62182 Pega Customer Service Framework versions 8.7.0 through 25.1.0 are affected by a Unrestricted file upload vulnerability, where a privileged user could potentially upload a malicious file. CWE-434 7.2AI High AI 2026-01-13
CVE-2025-62181 Pega Platform versions 7.1.0 through Infinity 25.1.0 are affected by a User Enumeration where during user authentication process, a difference in response time could allow a remote unauthenticated user to determine if a username is valid or not. CWE-204 5.3 Medium 2025-12-10
CVE-2025-9559 Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user interface component that can only be used to read data CWE-639 6.5 Medium 2025-10-16
CVE-2025-8681 Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component CWE-79 5.5 Medium 2025-09-10
CVE-2025-2161 Pegasystem Pega Platform 安全漏洞 CWE-79 7.1 High 2025-04-14
CVE-2025-2160 Pegasystem Pega Platform 安全漏洞 CWE-79 8.1 High 2025-04-14
CVE-2024-12211 Pegasystem PEGA Platform 安全漏洞 CWE-79 5.4 Medium 2025-01-13
CVE-2024-10716 Pegasystem PEGA Platform 安全漏洞 CWE-79 5.9 Medium 2024-12-05
CVE-2024-10094 Pegasystem PEGA Platform 安全漏洞 CWE-94 9.1 Critical 2024-11-20
CVE-2024-6702 Pegasystem PEGA Platform 安全漏洞 CWE-74 5.2 Medium 2024-09-12
CVE-2024-6701 Pegasystem PEGA Platform 安全漏洞 CWE-79 5.5 Medium 2024-09-12
CVE-2024-6700 Pegasystem PEGA Platform 安全漏洞 CWE-79 5.5 Medium 2024-09-12
CVE-2023-26465 Pegasystem PEGA Platform 跨站脚本漏洞 CWE-79 6.1 - 2023-06-09
CVE-2022-35656 Pegasystem PEGA Platform 跨站请求伪造漏洞 CWE-352 4.5 - 2022-08-22
CVE-2022-35655 Pegasystem PEGA Platform 跨站脚本漏洞 CWE-79 6.1 - 2022-08-22
CVE-2022-35654 Pegasystem PEGA Platform 跨站脚本漏洞 CWE-79 6.1 - 2022-08-22
CVE-2022-24083 Pegasystem Pega 安全漏洞 CWE-285 8.4 - 2022-07-25
CVE-2022-24082 Pegasystem PEGA Platform 代码问题漏洞 CWE-502 9.8 - 2022-07-19
CVE-2021-27654 Pegasystems Pega 授权问题漏洞 CWE-640 7.8 - 2022-01-28
CVE-2021-27651 PEGA pega infinity 授权问题漏洞 CWE-287 7.8 - 2021-04-29

All 31 known CVE vulnerabilities affecting Pega Infinity with full Chinese analysis, references, and POCs where available.