CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2022-31358

Critical · CVSS 9.0

Proxmox Virtual Environment (pve-http-server) — Reflected Cross-Site Scripting (XSS) via non-existent API endpoint path

CVSS
9.0
nvd
EPSS
KEV
No
Class
other
CWE-79, CWE-79

Description

A reflected cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment prior to v7.2-3 allows remote attackers to execute arbitrary web scripts or HTML via non-existent endpoints under path /api2/html/.

Search profile — drives PoC discovery

Symbols pve-http-server/api2/html/00661f1223b7c0afffa64e1d91f5e018b985f762pve_http_serverrender_html_404
Keywords CVE-2022-31358Proxmox VE XSSProxmox reflected XSSpve-http-server XSS/api2/html/ XSSProxmox non-existent endpoint XSSProxmox 7.2 XSS PoCstarlabs proxmox vulnerabilities
Versions: Proxmox Virtual Environment < 7.2-3

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T12:30:39.000Z