← Back

Nginx Proxy Manager

nginx_proxy_manager

Vendor: Jc21 • 7 CVEs

CVEs (7)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jc21
1Nginx Proxy Manager
Jun 17, 2026
Aug 19, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A CORS misconfiguration in Nginx Proxy Manager v2.12.3 allows unauthorized domains to access sensitive data, particularly JWT tokens, due to improper validation of the Origin header. This misconfiguration enables attacke...Show more
A CORS misconfiguration in Nginx Proxy Manager v2.12.3 allows unauthorized domains to access sensitive data, particularly JWT tokens, due to improper validation of the Origin header. This misconfiguration enables attackers to intercept tokens using a simple browser script and exfiltrate them to a remote attacker-controlled server, potentially leading to unauthorized actions within the application.Show less
1Jc21
1Nginx Proxy Manager
Jun 17, 2026
Sep 27, 2024
N/A· v4
6.3 MEDIUM· v3
N/A· v2
A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacker to achieve remote code execution via Add Let's Encrypt Certificate. NOTE: this is not part of any...Show more
A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacker to achieve remote code execution via Add Let's Encrypt Certificate. NOTE: this is not part of any NGINX software shipped by F5.Show less
1Jc21
1Nginx Proxy Manager
Jun 17, 2026
Sep 27, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add Let's Encrypt Certificate.
1Jc21
1Nginx Proxy Manager
Jun 17, 2026
Jul 4, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
jc21 NGINX Proxy Manager before 2.11.3 allows backend/internal/certificate.js OS command injection by an authenticated user (with certificate management privileges) via untrusted input to the DNS provider configuration....Show more
jc21 NGINX Proxy Manager before 2.11.3 allows backend/internal/certificate.js OS command injection by an authenticated user (with certificate management privileges) via untrusted input to the DNS provider configuration. NOTE: this is not part of any NGINX software shipped by F5.Show less
1Jc21
1Nginx Proxy Manager
Jun 17, 2026
Mar 22, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue found in NginxProxyManager v.2.9.19 allows an attacker to execute arbitrary code via a lua script to the configuration file.
1Jc21
1Nginx Proxy Manager
Jun 17, 2026
Jan 20, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection. When creating an access list, the backend builds an htpasswd file with crafted username and/or password input that is concatenated without any validati...Show more
jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection. When creating an access list, the backend builds an htpasswd file with crafted username and/or password input that is concatenated without any validation, and is directly passed to the exec command, potentially allowing an authenticated attacker to execute arbitrary commands on the system. NOTE: this is not part of any NGINX software shipped by F5.Show less
1Jc21
1Nginx Proxy Manager
Jun 17, 2026
Aug 23, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
jc21 Nginx Proxy Manager before 2.0.13 allows %2e%2e%2f directory traversal.