Nginx Proxy Manager
Jc21 · 7 CVEs
A CORS misconfiguration in Nginx Proxy Manager v2.12.3 allows unauthorized domains to access sensitive data, particular…
Aug 19, 2025
A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attack…
Sep 27, 2024
A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Ad…
Sep 27, 2024
jc21 NGINX Proxy Manager before 2.11.3 allows backend/internal/certificate.js OS command injection by an authenticated…
Jul 4, 2024
An issue found in NginxProxyManager v.2.9.19 allows an attacker to execute arbitrary code via a lua script to the confi…
Mar 22, 2023
jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection. When creating an access list, the backend builds a…
Jan 20, 2023
jc21 Nginx Proxy Manager before 2.0.13 allows %2e%2e%2f directory traversal.
Aug 23, 2019
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-50579 | A CORS misconfiguration in Nginx Proxy Manager v2.12.3 allows unauthorized domains to access sensitive data, particularly JWT tokens, due to improper validatio… | MEDIUM | 0.38% | Aug 19, 2025 |
| CVE-2024-46257 | A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacker to achieve remote code execution via… | MEDIUM | 1.33% | Sep 27, 2024 |
| CVE-2024-46256 | A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add Let's Encrypt Certificate. | CRITICAL | 3.08% | Sep 27, 2024 |
| CVE-2024-39935 | jc21 NGINX Proxy Manager before 2.11.3 allows backend/internal/certificate.js OS command injection by an authenticated user (with certificate management privil… | HIGH | 0.88% | Jul 4, 2024 |
| CVE-2023-27224 | An issue found in NginxProxyManager v.2.9.19 allows an attacker to execute arbitrary code via a lua script to the configuration file. | CRITICAL | 1.22% | Mar 22, 2023 |
| CVE-2023-23596 | jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection. When creating an access list, the backend builds an htpasswd file with crafted username an… | HIGH | 15.20% | Jan 20, 2023 |
| CVE-2019-15517 | jc21 Nginx Proxy Manager before 2.0.13 allows %2e%2e%2f directory traversal. | MEDIUM | 0.73% | Aug 23, 2019 |
Showing 1 to 7 of 7 CVEs