Cloudstack

Vendor:

First CVE: Oct 26, 2012 · Active for 13 years

45
Total CVEs
More Total CVEs than 97% of tracked products
4.1
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Cloudstack over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 26, 2012
13 years ago
Most Recent CVE
May 8, 2026
77 days ago

CVE Severity & Scoring

Cloudstack45 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local1 (2.2%)
Network35 (77.8%)
Unknown9 (20.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low31 (68.9%)
High5 (11.1%)
Unknown9 (20.0%)
User Interaction
None34 (75.6%)
Unknown9 (20.0%)
Required2 (4.4%)
Privileges Required
Low19 (42.2%)
High4 (8.9%)
None13 (28.9%)
Unknown9 (20.0%)

Top CVEs

Signals from CVEs in this product scope (45 CVEs).

45 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The CloudStack SAML authentication (disabled by default) does not enforce signature check. In CloudStack environments where SAML authentication is enabled, an attacker that initiat
Jul 19, 20248.146NOYES
Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants. This issue affects Apache CloudStack: from 4.21.0.0 through 4.22
May 8, 20269.135NONO
Apache CloudStack version 4.5.0 and later has a SAML 2.0 authentication Service Provider plugin which is found to be vulnerable to XML external entity (XXE) injection. This plugin
Jul 18, 20229.835NONO
Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user account, as demonstrated by API ca
Oct 26, 201210.035NONO
Account users are allowed by default to register templates to be downloaded directly to the primary storage for deploying instances using the KVM hypervisor. Due to missing file na
May 8, 20268.834NONO
Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which they previously owned. If another user creates a new bucket wit
May 8, 20268.132NONO
The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, whe
May 8, 20268.132NONO
The CloudStack cluster service runs on unauthenticated port (default 9090) that can be misused to run arbitrary commands on targeted hypervisors and CloudStack management server ho
Jul 5, 20249.832NONO
A buffer overflow vulnerability has been found in the baremetal component of Apache CloudStack. This applies to all versions prior to 4.13.1. The vulnerability is due to the lack o
May 14, 20209.832NONO
Apache CloudStack 4.1 to 4.8.1.0 and 4.9.0.0 contain an API call designed to allow a user to register for the developer API. If a malicious user is able to determine the ID of anot
Feb 6, 20189.832NONO

Exploit Exposure

Signals from CVEs in this product scope (45 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
2.2% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (45 CVEs).

Media Mentions

Signals from CVEs in this product scope (45 CVEs).

Top CNAs Publishing CVEs For Cloudstack

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.9.019.85.6%00
4.816.52.9%00
4.7.016.52.9%00
4.6.216.52.9%00
4.6.116.52.9%00
4.6.016.52.9%00
4.5.216.52.9%00
4.5.125.72.7%00
4.4.414.92.5%00
4.4.125.02.9%00
4.4.025.02.9%00
4.3.115.02.6%00
4.3.015.02.6%00
4.21.0.024.50.4%00
4.20.0.014.30.7%00
4.19.1.014.31.0%00
4.19.0.037.80.8%00
4.17.0.019.87.9%00
4.1.133.72.3%00
4.1.033.72.3%00