CVE-2022-31358EPSS p69.2%

CVE-2022-31358CVE-2022-31358

proxmox / virtual_environment

Description

A reflected cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment prior to v7.2-3 allows remote attackers to execute arbitrary web scripts or HTML via non-existent endpoints under path /api2/html/.

Scoring

CVSS 9.0 ()
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
EPSS1.29% probability of exploitation · percentile 69.2% · 2026-10-05T12:00:23Z
Last modified2026-07-09
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.