NginxProxyManager
Products
1- 9 CVEs
Recent CVEs
9| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-27224 | Cri | 0.64 | 9.8 | 0.01 | Mar 22, 2023 | An issue found in NginxProxyManager v.2.9.19 allows an attacker to execute arbitrary code via a lua script to the configuration file. | ||
| CVE-2023-23596 | Hig | 0.58 | 8.8 | 0.15 | Jan 20, 2023 | jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection. When creating an access list, the backend builds an htpasswd file with crafted username and/or password input that is concatenated without any validation, and is directly passed to the exec command, potentially… | ||
| CVE-2024-39935 | Hig | 0.50 | 8.8 | 0.01 | Jul 4, 2024 | jc21 NGINX Proxy Manager before 2.11.3 allows backend/internal/certificate.js OS command injection by an authenticated user (with certificate management privileges) via untrusted input to the DNS provider configuration. NOTE: this is not part of any NGINX software shipped by F5. | ||
| CVE-2022-28379 | Med | 0.50 | 6.8 | 0.71 | Apr 3, 2022 | jc21.com Nginx Proxy Manager before 2.9.17 allows XSS during item deletion. | ||
| CVE-2026-50892 | Med | 0.42 | 6.5 | 0.00 | Jun 15, 2026 | Incorrect access control in the "Let's Encrypt" certificate download endpoint of Nginx Proxy Manager v2.14.0 allows authenticated attackers to obtain the TLS private key material via a crafted GET request. | ||
| CVE-2026-40519 | Hig | 0.42 | 7.5 | 0.01 | Jun 8, 2026 | Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticated remote code execution vulnerability via OS command injection in the setupCertbotPlugins() function in backend/setup.js, allowing attackers with certificates:manage permission to… | ||
| CVE-2025-50579 | Med | 0.34 | 5.3 | 0.00 | Aug 19, 2025 | A CORS misconfiguration in Nginx Proxy Manager v2.12.3 allows unauthorized domains to access sensitive data, particularly JWT tokens, due to improper validation of the Origin header. This misconfiguration enables attackers to intercept tokens using a simple browser script and… | ||
| CVE-2024-46257 | Med | 0.00 | 6.3 | 0.01 | Sep 27, 2024 | A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacker to achieve remote code execution via Add Let's Encrypt Certificate. NOTE: this is not part of any NGINX software shipped by F5. | ||
| CVE-2024-46256 | Cri | 0.00 | 9.8 | 0.03 | Sep 27, 2024 | A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add Let's Encrypt Certificate. |
- risk 0.64cvss 9.8epss 0.01
An issue found in NginxProxyManager v.2.9.19 allows an attacker to execute arbitrary code via a lua script to the configuration file.
- risk 0.58cvss 8.8epss 0.15
jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection. When creating an access list, the backend builds an htpasswd file with crafted username and/or password input that is concatenated without any validation, and is directly passed to the exec command, potentially…
- risk 0.50cvss 8.8epss 0.01
jc21 NGINX Proxy Manager before 2.11.3 allows backend/internal/certificate.js OS command injection by an authenticated user (with certificate management privileges) via untrusted input to the DNS provider configuration. NOTE: this is not part of any NGINX software shipped by F5.
- risk 0.50cvss 6.8epss 0.71
jc21.com Nginx Proxy Manager before 2.9.17 allows XSS during item deletion.
- risk 0.42cvss 6.5epss 0.00
Incorrect access control in the "Let's Encrypt" certificate download endpoint of Nginx Proxy Manager v2.14.0 allows authenticated attackers to obtain the TLS private key material via a crafted GET request.
- risk 0.42cvss 7.5epss 0.01
Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticated remote code execution vulnerability via OS command injection in the setupCertbotPlugins() function in backend/setup.js, allowing attackers with certificates:manage permission to…
- risk 0.34cvss 5.3epss 0.00
A CORS misconfiguration in Nginx Proxy Manager v2.12.3 allows unauthorized domains to access sensitive data, particularly JWT tokens, due to improper validation of the Origin header. This misconfiguration enables attackers to intercept tokens using a simple browser script and…
- risk 0.00cvss 6.3epss 0.01
A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacker to achieve remote code execution via Add Let's Encrypt Certificate. NOTE: this is not part of any NGINX software shipped by F5.
- risk 0.00cvss 9.8epss 0.03
A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add Let's Encrypt Certificate.