CVE-2026-102335
- EPSS 0.23%
- Veröffentlicht 28.09.2026 23:17:02
- Zuletzt bearbeitet 30.09.2026 15:22:20
Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives. Attackers can inject malicious nginx configuration such as alias ...
CVE-2026-102334
- EPSS 0.45%
- Veröffentlicht 28.09.2026 23:17:01
- Zuletzt bearbeitet 29.09.2026 21:35:07
Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login credentials via POST /api/tokens and subseq...
CVE-2026-93964
- EPSS 0.27%
- Veröffentlicht 20.09.2026 05:30:17
- Zuletzt bearbeitet 22.09.2026 16:18:14
A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCertificate.validate of the file backend/internal/certificate.js of the component Validate Route. The manipulation results in missin...
CVE-2026-40519
- EPSS 0.92%
- Veröffentlicht 08.06.2026 19:28:51
- Zuletzt bearbeitet 23.07.2026 08:10:00
Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticated remote code execution vulnerability via OS command injection in the setupCertbotPlugins() function in backend/setup.js, allowing attackers with cert...
CVE-2024-46256
- EPSS 3.08%
- Veröffentlicht 27.09.2024 18:15:05
- Zuletzt bearbeitet 03.06.2025 11:55:42
A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add Let's Encrypt Certificate.
CVE-2024-46257
- EPSS 1.34%
- Veröffentlicht 27.09.2024 18:15:05
- Zuletzt bearbeitet 03.06.2025 11:55:19
A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacker to achieve remote code execution via Add Let's Encrypt Certificate. NOTE: this is not part of any NGINX software shipped by F5.
CVE-2022-28379
- EPSS 71.21%
- Veröffentlicht 03.04.2022 18:15:07
- Zuletzt bearbeitet 21.11.2024 06:57:15
jc21.com Nginx Proxy Manager before 2.9.17 allows XSS during item deletion.