VYPR

X UI

by Vaxilu

Source repositories

CVEs (3)

  • CVE-2026-79314HigSep 22, 2026
    risk 0.57cvss 8.8epss 0.00

    A horizontal privilege escalation vulnerability exists in x-ui 0.3.2. An authenticated user can modify the inbound proxy configurations of other users, including remark, port, protocol, settings, enabled state, expiry time and traffic quota, by submitting a request referencing…

  • CVE-2023-41595HigSep 18, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in xui-xray v1.8.3 allows attackers to obtain sensitive information via default password.

  • CVE-2026-79315MedSep 22, 2026
    risk 0.31cvss 4.7epss 0.00

    A reflected cross-site scripting vulnerability exists in x-ui 0.3.2. The management interface reflects the raw request URI into a client-side template binding expression used for sidebar menu highlighting. Server-side HTML entity escaping is ineffective in this context: the…