Nginxproxymanager

Nginx Proxy Manager

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.23%
  • Veröffentlicht 28.09.2026 23:17:02
  • Zuletzt bearbeitet 30.09.2026 15:22:20

Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives. Attackers can inject malicious nginx configuration such as alias ...

  • EPSS 0.45%
  • Veröffentlicht 28.09.2026 23:17:01
  • Zuletzt bearbeitet 29.09.2026 21:35:07

Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login credentials via POST /api/tokens and subseq...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 20.09.2026 05:30:17
  • Zuletzt bearbeitet 22.09.2026 16:18:14

A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCertificate.validate of the file backend/internal/certificate.js of the component Validate Route. The manipulation results in missin...

  • EPSS 0.92%
  • Veröffentlicht 08.06.2026 19:28:51
  • Zuletzt bearbeitet 23.07.2026 08:10:00

Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticated remote code execution vulnerability via OS command injection in the setupCertbotPlugins() function in backend/setup.js, allowing attackers with cert...

Exploit
  • EPSS 3.08%
  • Veröffentlicht 27.09.2024 18:15:05
  • Zuletzt bearbeitet 03.06.2025 11:55:42

A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add Let's Encrypt Certificate.

Exploit
  • EPSS 1.34%
  • Veröffentlicht 27.09.2024 18:15:05
  • Zuletzt bearbeitet 03.06.2025 11:55:19

A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacker to achieve remote code execution via Add Let's Encrypt Certificate. NOTE: this is not part of any NGINX software shipped by F5.

Exploit
  • EPSS 71.21%
  • Veröffentlicht 03.04.2022 18:15:07
  • Zuletzt bearbeitet 21.11.2024 06:57:15

jc21.com Nginx Proxy Manager before 2.9.17 allows XSS during item deletion.