CVE-2025-9559Medium· 6.5▾ SunlitPega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user interface component that can only be used to read data.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user interface component that can only be used to read data.
pega_platform >= 7.1.0, < 23.1.5pega_platform >= 24.1.0, <= 24.1.3pega_platform >= 24.2.0, <= 24.2.2Upgrade past the affected range:
pega_platform 23.1.5Connected by shared product, vendor, weakness, or advisory.
CVE-2025-8681Medium· 5.5Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component
CVE-2025-62184Low· 3.4Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interface component
CVE-2025-12288Medium· 4.3A vulnerability was detected in Bdtask Pharmacy Management System up to 9.4
CVE-2025-12283Medium· 4.3A security flaw has been discovered in code-projects Client Details System 1.0
CVE-2021-46416High· 8.1Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.
CVE-2025-14459High· 8.5A flaw was found in KubeVirt Containerized Data Importer (CDI)