cvemon logocvemon logo

Insights

CVE-2025-2160

Published Apr 14, 2025

Last updated a month ago

CVSS high 8.1
  1. Overview

  2. Scores

  3. Weaknesses

  4. Social media

  5. References

Overview

Description
Pega Platform versions 8.4.3 to Infinity 24.2.1 are affected by an XSS issue with Mashup
Source
security@pega.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.1
Impact score
5.2
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Severity
HIGH

Weaknesses

security@pega.com
CWE-79

Social media

Hype score
Not currently trending
  1. CVE-2025-2160 (CVSS:8.1, HIGH) is Awaiting Analysis. Pega Platform versions 8.4.3 to Infinity 24.2.1 are affected by an XSS issue with Mashup..https://t.co/BWbsZHlJDI #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    19 Apr 2025

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Warning: 2 high #XSS in @Pega CVE-2025-2160 CVE-2025-2161 CVSS: 8.1-7.1. An unauthenticated remote attacker with user interaction and without privileges can inject malicious scripts to be executed in a victims web browser (cross-site scripting) #Patch https://t.co/DTSqDKrj2z

    @CCBalert

    15 Apr 2025

    172 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.

  • https://nvd.nist.gov/vuln/detail/CVE-2025-2160
  • https://support.pega.com/support-doc/pega-security-advisory-d25-vulnerability-remediation-note
TRY INTRUDER
Intruder logo

© 2025 Intruder Systems Ltd.

AboutPrivacySitemapFeeds