Vaxilu
Vaxilu X-ui: vulnerabilidades y CVE
Vaxilu X-ui tiene 5 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE5
Últimos 12 meses4
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-79315 | Media (4.7) | 0.27% | — | 22 sept 2026 | A reflected cross-site scripting vulnerability exists in x-ui 0.3.2. The management interface reflects the raw request URI into a client-side template binding expression used for sidebar menu highlighting. Server-side… |
| CVE-2026-79314 | Alta (8.8) | 0.30% | — | 22 sept 2026 | A horizontal privilege escalation vulnerability exists in x-ui 0.3.2. An authenticated user can modify the inbound proxy configurations of other users, including remark, port, protocol, settings, enabled state, expiry… |
| CVE-2026-79317 | Media (4.8) | 0.29% | — | 21 sept 2026 | A session invalidation flaw exists in x-ui 0.3.2. The full user object is stored in a client-side signed cookie, and authentication only checks that a user object can be retrieved from the cookie without re-validating… |
| CVE-2026-79316 | Alta (7.6) | 0.32% | — | 21 sept 2026 | An improper access control vulnerability exists in x-ui 0.3.2. Any authenticated panel user can modify the xray configuration template through the settings interface and trigger a panel restart, causing the xray… |
| CVE-2023-41595 | Alta (7.5) | 0.55% | — | 18 sept 2023 | An issue in xui-xray v1.8.3 allows attackers to obtain sensitive information via default password. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.