OpenNebula is a niche infrastructure-as-a-service and virtualization platform whose vulnerability footprint centers on its core management application. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated tendency toward critical severity, and recur through input-handling weakness classes including cross-site scripting, command injection, improper file access control, and unsafe file upload handling that reflect the web interface and system-integration demands of a cloud-orchestration platform. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opennebula over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-37425CRITICAL Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in OpenNebula OpenNebula core on Linux allows Remote Code Inclusion. | Oct 28, 2022 | 9.8 | 30 | NO | NO |
CVE-2025-56537MEDIUM A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 and fixed in v.7.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted paylo | Apr 29, 2026 | 6.1 | 24 | NO | NO |
CVE-2025-56536MEDIUM A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the user in | Apr 29, 2026 | 6.1 | 24 | NO | NO |
CVE-2025-56535MEDIUM A cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the zone attribute | Apr 29, 2026 | 6.1 | 24 | NO | NO |
CVE-2025-56534MEDIUM A cross-site scripting (XSS) vulnerability in the custom authenticator driver of opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payloa | Apr 29, 2026 | 6.1 | 24 | NO | NO |
CVE-2022-37426HIGH Unrestricted Upload of File with Dangerous Type vulnerability in OpenNebula OpenNebula core on Linux allows File Content Injection. | Oct 28, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-37424MEDIUM Files or Directories Accessible to External Parties vulnerability in OpenNebula on Linux allows File Discovery. | Oct 28, 2022 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opennebula.
Media articles that mention a CVE ID that affects a product developed by Opennebula — matched by CVE ID, not by vendor name.