Proxmox develops a compact portfolio of virtualization and infrastructure management products—including its core virtual-environment hypervisor, mail gateway, and backup appliance—that serve as control planes for enterprise environments and present a meaningful attack surface despite the focused product range. Vulnerabilities affecting the vendor skew toward serious outcomes and cluster around web-tier input-handling weakness classes including cross-site scripting, injection, and server-side request forgery, reflecting the web-exposed management interfaces across these products. The vendor's disclosures tend to acquire public exploit tooling, underscoring the appeal of these management-layer targets to attackers. Defenders should prioritize patching of exposed management interfaces and restrict network access to these administrative services; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Proxmox over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-35507HIGH A response-header CRLF injection vulnerability in the Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) web interface allows a remote attacker to set cookies for a v | Dec 4, 2022 | 7.1 | 34 | NO | YES |
CVE-2022-35508CRITICAL Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) are vulnerable to SSRF when proxying HTTP requests between pve(pmg)proxy and pve(pmg)daemon. An attacker with an un | Dec 4, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-31358CRITICAL A reflected cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment prior to v7.2-3 allows remote attackers to execute arbitrary web scripts or HTML via non-existen | Dec 14, 2022 | 9.0 | 30 | NO | NO |
CVE-2023-43320HIGH An issue in Proxmox Server Solutions GmbH Proxmox VE v.5.4 thru v.8.0, Proxmox Backup Server v.1.1 thru v.3.0, and Proxmox Mail Gateway v.7.1 thru v.8.0 allows a remote authenticat | Sep 27, 2023 | 8.8 | 25 | NO | NO |
CVE-2015-9057MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Proxmox Mail Gateway prior to hotfix 4.0-8-097d26a9 allow remote attackers to inject arbitrary web script or HTML via multipl | May 3, 2017 | 6.1 | 21 | NO | NO |
CVE-2025-57540MEDIUM A stored cross-site scripting (XSS) vulnerability exists in the WebAuthn Relying Party field within the Datacenter configuration of Proxmox Virtual Environment (PVE) 8.4. Authentic | Sep 9, 2025 | 5.4 | 20 | NO | NO |
CVE-2025-57539MEDIUM A stored cross-site scripting (XSS) vulnerability in the U2F Origin field of the Datacenter configuration in Proxmox Virtual Environment (PVE) 8.4 allows authenticated users to sto | Sep 9, 2025 | 5.4 | 20 | NO | NO |
CVE-2025-57538MEDIUM A stored cross-site scripting (XSS) vulnerability in the HTTP Proxy field within the Datacenter configuration panel of Proxmox Virtual Environment (PVE) 8.4 allows an authenticated | Sep 9, 2025 | 5.4 | 20 | NO | NO |
CVE-2023-46854MEDIUM Proxmox proxmox-widget-toolkit before 4.0.9, as used in multiple Proxmox products, allows XSS via the edit notes feature. | Oct 28, 2023 | 6.1 | 20 | NO | NO |
CVE-2015-9058MEDIUM Open redirect vulnerability in Proxmox Mail Gateway prior to hotfix 4.0-8-097d26a9 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via | May 3, 2017 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Proxmox.
Media articles that mention a CVE ID that affects a product developed by Proxmox — matched by CVE ID, not by vendor name.