X UI
by Vaxilu
Source repositories
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-79314 | Hig | 0.57 | 8.8 | 0.00 | Sep 22, 2026 | A horizontal privilege escalation vulnerability exists in x-ui 0.3.2. An authenticated user can modify the inbound proxy configurations of other users, including remark, port, protocol, settings, enabled state, expiry time and traffic quota, by submitting a request referencing… | ||
| CVE-2023-41595 | Hig | 0.49 | 7.5 | 0.01 | Sep 18, 2023 | An issue in xui-xray v1.8.3 allows attackers to obtain sensitive information via default password. | ||
| CVE-2026-79315 | Med | 0.31 | 4.7 | 0.00 | Sep 22, 2026 | A reflected cross-site scripting vulnerability exists in x-ui 0.3.2. The management interface reflects the raw request URI into a client-side template binding expression used for sidebar menu highlighting. Server-side HTML entity escaping is ineffective in this context: the… |
- risk 0.57cvss 8.8epss 0.00
A horizontal privilege escalation vulnerability exists in x-ui 0.3.2. An authenticated user can modify the inbound proxy configurations of other users, including remark, port, protocol, settings, enabled state, expiry time and traffic quota, by submitting a request referencing…
- risk 0.49cvss 7.5epss 0.01
An issue in xui-xray v1.8.3 allows attackers to obtain sensitive information via default password.
- risk 0.31cvss 4.7epss 0.00
A reflected cross-site scripting vulnerability exists in x-ui 0.3.2. The management interface reflects the raw request URI into a client-side template binding expression used for sidebar menu highlighting. Server-side HTML entity escaping is ineffective in this context: the…