« Volver al listado

Nginxproxymanager

Nginxproxymanager Nginx Proxy Manager: vulnerabilidades y CVE

Nginxproxymanager Nginx Proxy Manager tiene 5 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE5
Últimos 12 meses4
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-102335Alta (7.1)0.23%—28 sept 2026
Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives. Attackers can inject malicious…
CVE-2026-102334Crítica (9.1)0.45%—28 sept 2026
Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login credentials…
CVE-2026-93964Media (5.5)0.45%—20 sept 2026
A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCertificate.validate of the file backend/internal/certificate.js of the component Validate Route. The…
CVE-2026-40519Alta (7.7)1.7%—8 jun 2026
Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticated remote code execution vulnerability via OS command injection in the setupCertbotPlugins() function in…
CVE-2022-28379Media (4.8)71%—3 abr 2022
jc21.com Nginx Proxy Manager before 2.9.17 allows XSS during item deletion.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1078 Valid Accounts2
  2. T1190 Exploit Public-Facing Application2
  3. T1078.004 Cloud Accounts1
  4. T1210 Exploitation of Remote Services1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.