« Back to list

Nginxproxymanager

Nginxproxymanager Nginx Proxy Manager: vulnerabilities and CVEs

Nginxproxymanager Nginx Proxy Manager has 5 published vulnerabilities, 4 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs5
Last 12 months4
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-102335High (7.1)0.23%—Sep 28, 2026
Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives. Attackers can inject malicious…
CVE-2026-102334Critical (9.1)0.45%—Sep 28, 2026
Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login credentials…
CVE-2026-93964Medium (5.5)0.45%—Sep 20, 2026
A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCertificate.validate of the file backend/internal/certificate.js of the component Validate Route. The…
CVE-2026-40519High (7.7)1.7%—Jun 8, 2026
Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticated remote code execution vulnerability via OS command injection in the setupCertbotPlugins() function in…
CVE-2022-28379Medium (4.8)71%—Apr 3, 2022
jc21.com Nginx Proxy Manager before 2.9.17 allows XSS during item deletion.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1078 Valid Accounts2
  2. T1190 Exploit Public-Facing Application2
  3. T1210 Exploitation of Remote Services2
  4. T1059 Command and Scripting Interpreter1
  5. T1078.004 Cloud Accounts1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.