proxmox CVE Vulnerabilities & Metrics

Focus on proxmox vulnerabilities and metrics.

Last updated: 25 Nov 2025, 23:25 UTC

About proxmox Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with proxmox. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total proxmox CVEs: 10
Earliest CVE date: 14 Mar 2014, 14:55 UTC
Latest CVE date: 09 Sep 2025, 17:16 UTC

Latest CVE reference: CVE-2025-57540

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 3

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical proxmox CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 1.76

Max CVSS: 5.8

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 7
4.0-6.9 4
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS proxmox CVEs

These are the five CVEs with the highest CVSS scores for proxmox, sorted by severity first and recency.

All CVEs for proxmox

CVE-2025-57540 proxmox vulnerability CVSS: 0 09 Sep 2025, 17:16 UTC

A stored cross-site scripting (XSS) vulnerability exists in the WebAuthn Relying Party field within the Datacenter configuration of Proxmox Virtual Environment (PVE) 8.4. Authenticated users can inject JavaScript code that is later executed in the browsers of users who view the configuration page, enabling client-side attacks.

CVE-2025-57539 proxmox vulnerability CVSS: 0 09 Sep 2025, 17:16 UTC

A stored cross-site scripting (XSS) vulnerability in the U2F Origin field of the Datacenter configuration in Proxmox Virtual Environment (PVE) 8.4 allows authenticated users to store malicious input. The payload is rendered unsafely in the Web UI and executed when viewed by other users, potentially leading to session hijacking or other attacks.

CVE-2025-57538 proxmox vulnerability CVSS: 0 09 Sep 2025, 17:16 UTC

A stored cross-site scripting (XSS) vulnerability in the HTTP Proxy field within the Datacenter configuration panel of Proxmox Virtual Environment (PVE) 8.4 allows an authenticated user to inject malicious input. The input is stored and executed in the context of other users' browsers when they view the affected configuration page. This can lead to arbitrary JavaScript execution.

CVE-2023-43320 proxmox vulnerability CVSS: 0 27 Sep 2023, 23:15 UTC

An issue in Proxmox Server Solutions GmbH Proxmox VE v.5.4 thru v.8.0, Proxmox Backup Server v.1.1 thru v.3.0, and Proxmox Mail Gateway v.7.1 thru v.8.0 allows a remote authenticated attacker to escalate privileges via bypassing the two-factor authentication component.

CVE-2022-31358 proxmox vulnerability CVSS: 0 14 Dec 2022, 15:15 UTC

A reflected cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment prior to v7.2-3 allows remote attackers to execute arbitrary web scripts or HTML via non-existent endpoints under path /api2/html/.

CVE-2022-35508 proxmox vulnerability CVSS: 0 04 Dec 2022, 19:15 UTC

Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) are vulnerable to SSRF when proxying HTTP requests between pve(pmg)proxy and pve(pmg)daemon. An attacker with an unprivileged account can craft an HTTP request to achieve SSRF and file disclosure of any files on the server. Also, in Proxmox Mail Gateway, privilege escalation to the root@pam account is possible if the backup feature has ever been used, because backup files such as pmg-backup_YYYY_MM_DD_*.tgz have 0644 permissions and contain an authkey value. This is fixed in pve-http-server 4.1-3.

CVE-2022-35507 proxmox vulnerability CVSS: 0 04 Dec 2022, 19:15 UTC

A response-header CRLF injection vulnerability in the Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) web interface allows a remote attacker to set cookies for a victim's browser that are longer than the server expects, causing a client-side DoS. This affects Chromium-based browsers because they allow injection of response headers with %0d. This is fixed in pve-http-server 4.1-3.

CVE-2014-4156 proxmox vulnerability CVSS: 5.0 27 Jan 2020, 15:15 UTC

Proxmox VE prior to 3.2: 'AccessControl.pm' User Enumeration Vulnerability

CVE-2015-9058 proxmox vulnerability CVSS: 5.8 03 May 2017, 10:59 UTC

Open redirect vulnerability in Proxmox Mail Gateway prior to hotfix 4.0-8-097d26a9 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the destination parameter.

CVE-2015-9057 proxmox vulnerability CVSS: 4.3 03 May 2017, 10:59 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Proxmox Mail Gateway prior to hotfix 4.0-8-097d26a9 allow remote attackers to inject arbitrary web script or HTML via multiple parameters, related to /users/index.htm, /quarantine/spam/manage.htm, /quarantine/spam/whitelist.htm, /queues/mail/index/, /system/ssh.htm, /queues/mail/?domain=, and /quarantine/virus/manage.htm.

CVE-2014-2325 proxmox vulnerability CVSS: 4.3 14 Mar 2014, 14:55 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Proxmox Mail Gateway before 3.1-5829 allow remote attackers to inject arbitrary web script or HTML via the (1) state parameter to objects/who/index.htm or (2) User email address to quarantine/spam/manage.htm.