PatchSiren

Pega CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Pega CVE published 2026-07-15

CVE-2026-1563

CVE-2026-1563 is a Reflected Cross-site scripting (XSS) vulnerability affecting Pega Platform versions 8.1.0 through 25.1.2. This vulnerability requires a high privileged user with a developer role and is located in a user interface component. The vulnerability has a CVSS score of 4.8 and a severity of MEDIUM. Users of Pega Platform versions 8.1.0 through 25.1.2, especially those with high privileges and [truncated]

MEDIUM Pega CVE published 2026-07-15

CVE-2026-1562

A Stored Cross-site scripting (XSS) vulnerability exists in Pega Platform versions 8.1.0 through 25.1.2. This vulnerability requires a high privileged user with a developer role to exploit. The vulnerability is a Stored Cross-site scripting (XSS) issue in a user interface component of Pega Platform. The Common Vulnerabilities and Exposures (CVE) score for this issue is 4.6, and the Common Vulnerability Sc [truncated]

MEDIUM Pega CVE published 2026-03-31

CVE-2025-62184

CVE-2025-62184 is a Stored Cross-site Scripting vulnerability in Pega Platform versions 8.1.0 through 25.1.0. The vulnerability requires an administrative user with extensive access rights, resulting in low impact to Confidentiality and no impact to Integrity. The vulnerability class is Stored Cross-site Scripting (XSS) in a user interface component. The likely operational impact is low, given the require [truncated]