« Volver al listado

Vaxilu

Vaxilu X-ui: vulnerabilidades y CVE

Vaxilu X-ui tiene 5 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE5
Últimos 12 meses4
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-79315Media (4.7)0.27%—22 sept 2026
A reflected cross-site scripting vulnerability exists in x-ui 0.3.2. The management interface reflects the raw request URI into a client-side template binding expression used for sidebar menu highlighting. Server-side…
CVE-2026-79314Alta (8.8)0.30%—22 sept 2026
A horizontal privilege escalation vulnerability exists in x-ui 0.3.2. An authenticated user can modify the inbound proxy configurations of other users, including remark, port, protocol, settings, enabled state, expiry…
CVE-2026-79317Media (4.8)0.29%—21 sept 2026
A session invalidation flaw exists in x-ui 0.3.2. The full user object is stored in a client-side signed cookie, and authentication only checks that a user object can be retrieved from the cookie without re-validating…
CVE-2026-79316Alta (7.6)0.32%—21 sept 2026
An improper access control vulnerability exists in x-ui 0.3.2. Any authenticated panel user can modify the xray configuration template through the settings interface and trigger a panel restart, causing the xray…
CVE-2023-41595Alta (7.5)0.55%—18 sept 2023
An issue in xui-xray v1.8.3 allows attackers to obtain sensitive information via default password.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services2
  2. T1059.007 JavaScript1
  3. T1078.001 Default Accounts1
  4. T1189 Drive-by Compromise1
  5. T1190 Exploit Public-Facing Application1
  6. T1548.004 Elevated Execution with Prompt1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.