---
id: CVE-2025-62184
title: >-
  Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored
  Cross-site Scripting vulnerability in a user interface component
summary: >-
  Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored
  Cross-site Scripting vulnerability in a user interface component.  Requires an
  administrative user and given extensive access rights, impact to
  Confidentiality is low a…
severity: low
cvss: 3.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:N/A:N'
cwe:
  - CWE-79
vendor: pega
product: pega_platform
affected:
  - 'pega_platform >= 8.1, <= 25.1.0'
published: '2026-03-31'
updated: '2026-07-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-62184'
references:
  - url: >-
      https://support.pega.com/support-doc/pega-security-advisory-o25-vulnerability-remediation-note
    label: security@pega.com
tags:
  - nvd
epss: 0.00258
epssPercentile: 0.15619
ingestedAt: '2026-07-24T20:38:02.975Z'
---

## Overview

Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interface component.  Requires an administrative user and given extensive access rights, impact to Confidentiality is low and Integrity is none.

## Affected

- `pega_platform >= 8.1, <= 25.1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
