Description
A cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment (PVE) 9.x 5.1.8 and Proxmox Virtual Environment (PVE) 8.x 4.3.16 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.
Published: 2026-07-17
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A cross‑site scripting (XSS) flaw exists in the web interface of Proxmox Virtual Environment. By injecting a crafted payload, an attacker can cause the browser to execute arbitrary JavaScript or render arbitrary HTML when a user visits a compromised page or loads a malicious link. This can lead to credential theft, session hijacking, defacement or the ability to run malicious code in the victim’s browser context, potentially affecting confidentiality, integrity or availability of the system.

Affected Systems

This vulnerability affects Proxmox Virtual Environment 9.x 5.1.8 and 8.x 4.3.16. Users running these exact versions should confirm whether upgrades are applicable or whether they remain in use.

Risk and Exploitability

The CVSS v3.1 score of 6.1 indicates moderate severity, but the EPSS score of less than 1% suggests a very low likelihood of widespread exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need to deliver or be able to inject the payload through the web UI, although the description does not specify authentication requirements; the attack vector is inferred to be the web interface. Given the moderate impact and low probability of exploitation, this represents a moderate operational risk pending remediation.

Generated by OpenCVE AI on August 1, 2026 at 08:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Proxmox Virtual Environment to a version not affected by this vulnerability.
  • Restrict external access to the Proxmox web interface by placing it behind a firewall or VPN, limiting the attack surface.
  • Deploy a web application firewall or implement content‑security‑policy headers to filter or block malicious scripts if an upgrade cannot be performed immediately.

Generated by OpenCVE AI on August 1, 2026 at 08:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting Vulnerability in Proxmox Virtual Environment Web Interface

Thu, 30 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Proxmox
Proxmox virtual Environment
Vendors & Products Proxmox
Proxmox virtual Environment

Tue, 28 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting Vulnerability in Proxmox Virtual Environment Web Interface

Sun, 26 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting in Proxmox Virtual Environment Web Interface

Wed, 22 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting in Proxmox Virtual Environment Web Interface

Fri, 17 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description A cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment (PVE) 9.x 5.1.8 and Proxmox Virtual Environment (PVE) 8.x 4.3.16 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.
References

Subscriptions

Proxmox Virtual Environment
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-17T15:13:18.023Z

Reserved: 2026-06-07T00:00:00.000Z

Link: CVE-2026-51081

cve-icon Vulnrichment

Updated: 2026-07-17T15:12:53.399Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T08:45:02Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')