Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Proxmox

First CVE: Mar 14, 2014Active for: 12 yearsTotal CVEs: 12
22.6
VTI Score
Low

Proxmox develops a compact portfolio of virtualization and infrastructure management products—including its core virtual-environment hypervisor, mail gateway, and backup appliance—that serve as control planes for enterprise environments and present a meaningful attack surface despite the focused product range. Vulnerabilities affecting the vendor skew toward serious outcomes and cluster around web-tier input-handling weakness classes including cross-site scripting, injection, and server-side request forgery, reflecting the web-exposed management interfaces across these products. The vendor's disclosures tend to acquire public exploit tooling, underscoring the appeal of these management-layer targets to attackers. Defenders should prioritize patching of exposed management interfaces and restrict network access to these administrative services; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Proxmox over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 14, 2014
12 years ago
Most Recent CVE
Sep 9, 2025
318 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-35507HIGH
A response-header CRLF injection vulnerability in the Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) web interface allows a remote attacker to set cookies for a v
Dec 4, 20227.134NOYES
CVE-2022-35508CRITICAL
Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) are vulnerable to SSRF when proxying HTTP requests between pve(pmg)proxy and pve(pmg)daemon. An attacker with an un
Dec 4, 20229.831NONO
CVE-2022-31358CRITICAL
A reflected cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment prior to v7.2-3 allows remote attackers to execute arbitrary web scripts or HTML via non-existen
Dec 14, 20229.030NONO
CVE-2023-43320HIGH
An issue in Proxmox Server Solutions GmbH Proxmox VE v.5.4 thru v.8.0, Proxmox Backup Server v.1.1 thru v.3.0, and Proxmox Mail Gateway v.7.1 thru v.8.0 allows a remote authenticat
Sep 27, 20238.825NONO
CVE-2015-9057MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Proxmox Mail Gateway prior to hotfix 4.0-8-097d26a9 allow remote attackers to inject arbitrary web script or HTML via multipl
May 3, 20176.121NONO
CVE-2025-57540MEDIUM
A stored cross-site scripting (XSS) vulnerability exists in the WebAuthn Relying Party field within the Datacenter configuration of Proxmox Virtual Environment (PVE) 8.4. Authentic
Sep 9, 20255.420NONO
CVE-2025-57539MEDIUM
A stored cross-site scripting (XSS) vulnerability in the U2F Origin field of the Datacenter configuration in Proxmox Virtual Environment (PVE) 8.4 allows authenticated users to sto
Sep 9, 20255.420NONO
CVE-2025-57538MEDIUM
A stored cross-site scripting (XSS) vulnerability in the HTTP Proxy field within the Datacenter configuration panel of Proxmox Virtual Environment (PVE) 8.4 allows an authenticated
Sep 9, 20255.420NONO
CVE-2023-46854MEDIUM
Proxmox proxmox-widget-toolkit before 4.0.9, as used in multiple Proxmox products, allows XSS via the edit notes feature.
Oct 28, 20236.120NONO
CVE-2015-9058MEDIUM
Open redirect vulnerability in Proxmox Mail Gateway prior to hotfix 4.0-8-097d26a9 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via
May 3, 20176.117NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
67%
17%
17%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (91.7%)
Unknown1 (8.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (91.7%)
High0 (0.0%)
Unknown1 (8.3%)
User Interaction
None3 (25.0%)
Unknown1 (8.3%)
Required8 (66.7%)
Privileges Required
Low5 (41.7%)
High0 (0.0%)
None6 (50.0%)
Unknown1 (8.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
8.3% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Proxmox.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Proxmox — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Proxmox's Products

View all 1 CNAs →

Top CWEs