nginxui records
23 published records for vendor nginxui.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 78.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-306 Missing Authentication for Critical Function3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
- CWE-284 Improper Access Control2
- CWE-20 Improper Input Validation2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
The weakness classes this vendor ships most often: where to look.
CWEAll records
23 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
43Plan | CVE-2024-49368Proof of concept | Unchecked logrotate settings lead to arbitrary command executionnginxui · nginx ui · CWE-20 | High8.9 | — | 27.7% | Oct 21, 2024 |
40Plan | CVE-2026-33032Proof of concept | Nginx UI: Unauthenticated MCP Endpoint Allows Remote Nginx Takeovernginxui · nginx ui · CWE-306 | Critical9.8 | — | 2.5% | Mar 30, 2026 |
39Monitor | CVE-2026-42221Proof of concept | nginx-ui: Unauthenticated First-Run Installer Allows Remote Initial Admin Claimnginxui · nginx ui · CWE-306 | Critical9.8 | — | 1.6% | May 4, 2026 |
39Monitor | CVE-2026-27944Proof of concept | Nginx UI: Unauthenticated Backup Download with Encryption Key Disclosurenginxui · nginx ui · CWE-306 | Critical9.8 | — | 1.0% | Mar 5, 2026 |
39Monitor | CVE-2024-23827No exploit | Nginx-UI arbitrary file write through the Import Certificate featurenginxui · nginx ui · CWE-22 | Critical9.8 | — | 0.7% | Jan 29, 2024 |
39Monitor | CVE-2026-42222No exploit | nginx-ui: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeovernginxui · nginx ui · CWE-284 | Critical9.8 | — | 0.5% | May 4, 2026 |
39Monitor | CVE-2026-44015No exploit | Nginx UI: Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware Allows Access to Internal Servicesnginxui · nginx ui · CWE-918 | Critical9.9 | — | 0.4% | May 12, 2026 |
39Monitor | CVE-2026-33030No exploit | Nginx UI: Unencrypted Storage of DNS API Tokens and ACME Private Keysnginxui · nginx ui · CWE-78 | Critical9.9 | — | 0.4% | Mar 30, 2026 |
37Monitor | CVE-2026-33026No exploit | nginx-ui Backup Restore Allows Tampering with Encrypted Backupsnginxui · nginx ui · CWE-312 | Critical9.4 | — | 0.2% | Mar 30, 2026 |
36Monitor | CVE-2024-22198Proof of concept | Authenticated (user role) arbitrary command execution by modifying `start_cmd` setting (GHSL-2023-268)nginxui · nginx ui · CWE-77 | High8.8 | — | 4.1% | Jan 11, 2024 |
36Monitor | CVE-2026-42238No exploit | Unauthenticated Remote Code Execution via Backup Restore in nginx-uinginxui · nginx ui · CWE-94 | Critical9.0 | — | 0.8% | May 4, 2026 |
35Monitor | CVE-2024-22197No exploit | Authenticated (user role) remote command execution by modifying `nginx` settings (GHSL-2023-269)nginxui · nginx ui · CWE-77 | High8.8 | — | 1.5% | Jan 11, 2024 |
35Monitor | CVE-2024-23828No exploit | Nginx-UI authenticated RCE through injecting into the application config via CRLFnginxui · nginx ui · CWE-74 | High8.8 | — | 1.1% | Jan 29, 2024 |
34Monitor | CVE-2026-33031No exploit | Nginx-UI: Disabled users retain full API access through previously issued bearer tokensnginxui · nginx ui · CWE-284 | High8.6 | — | 0.4% | Apr 20, 2026 |
30Monitor | CVE-2024-49366No exploit | Nginx UI's json field can construct a directory traversal payload, causing arbitrary files to be writtennginxui · nginx ui · CWE-22 | High7.7 | — | 0.6% | Oct 21, 2024 |
28Monitor | CVE-2026-33028No exploit | Nginx UI: Race Condition Leads to Persistent Data Corruption and Service Collapsenginxui · nginx ui · CWE-362 | High7.1 | — | 0.6% | Mar 30, 2026 |
27Monitor | CVE-2026-33027No exploit | Nginx UI: Improper Path Validation Allows Recursive Deletion of the Nginx Configuration Directorynginxui · nginx ui · CWE-22 | Medium6.9 | — | 0.5% | Mar 30, 2026 |
27Monitor | CVE-2026-33029No exploit | Nginx UI: DoS via Negative Integer Input in Logrotate Intervalnginxui · nginx ui · CWE-20 | Medium6.9 | — | 0.5% | Mar 30, 2026 |
26Monitor | CVE-2024-22196No exploit | Authenticated (user role) SQL injection in `OrderAndPaginate` (GHSL-2023-270)nginxui · nginx ui · CWE-89 | Medium6.5 | — | 0.6% | Jan 11, 2024 |
26Monitor | CVE-2026-42223No exploit | nginx-ui: Settings API Exposes Protected Secretsnginxui · nginx ui · CWE-200 | Medium6.5 | — | 0.4% | May 4, 2026 |
26Monitor | CVE-2026-42220No exploit | nginx-ui: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui snginxui · nginx ui · CWE-200 | Medium6.5 | — | 0.4% | May 4, 2026 |
22Monitor | CVE-2024-49367No exploit | Nginx UI's log path can be controllednginxui · nginx ui · CWE-862 | Medium5.5 | — | 0.6% | Oct 21, 2024 |
22Monitor | CVE-2026-34403No exploit | Nginx-UI vulnerable to Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpointsnginxui · nginx ui · CWE-1385 | Medium5.5 | — | 0.2% | Apr 20, 2026 |
- CVE-2024-4936843Plan
Unchecked logrotate settings lead to arbitrary command execution
HighCVSS 8.9Proof of conceptEPSS 28%nginxui · nginx uiOct 21, 2024
- CVE-2026-3303240Plan
Nginx UI: Unauthenticated MCP Endpoint Allows Remote Nginx Takeover
CriticalCVSS 9.8Proof of conceptEPSS 3%nginxui · nginx uiMar 30, 2026
- CVE-2026-4222139Monitor
nginx-ui: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim
CriticalCVSS 9.8Proof of conceptEPSS 2%nginxui · nginx uiMay 4, 2026
- CVE-2026-2794439Monitor
Nginx UI: Unauthenticated Backup Download with Encryption Key Disclosure
CriticalCVSS 9.8Proof of conceptEPSS 1%nginxui · nginx uiMar 5, 2026
- CVE-2024-2382739Monitor
Nginx-UI arbitrary file write through the Import Certificate feature
CriticalCVSS 9.8No exploitEPSS 1%nginxui · nginx uiJan 29, 2024
- CVE-2026-4222239Monitor
nginx-ui: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover
CriticalCVSS 9.8No exploitEPSS 0%nginxui · nginx uiMay 4, 2026
- CVE-2026-4401539Monitor
Nginx UI: Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware Allows Access to Internal Services
CriticalCVSS 9.9No exploitEPSS 0%nginxui · nginx uiMay 12, 2026
- CVE-2026-3303039Monitor
Nginx UI: Unencrypted Storage of DNS API Tokens and ACME Private Keys
CriticalCVSS 9.9No exploitEPSS 0%nginxui · nginx uiMar 30, 2026
- CVE-2026-3302637Monitor
nginx-ui Backup Restore Allows Tampering with Encrypted Backups
CriticalCVSS 9.4No exploitEPSS 0%nginxui · nginx uiMar 30, 2026
- CVE-2024-2219836Monitor
Authenticated (user role) arbitrary command execution by modifying `start_cmd` setting (GHSL-2023-268)
HighCVSS 8.8Proof of conceptEPSS 4%nginxui · nginx uiJan 11, 2024
- CVE-2026-4223836Monitor
Unauthenticated Remote Code Execution via Backup Restore in nginx-ui
CriticalCVSS 9.0No exploitEPSS 1%nginxui · nginx uiMay 4, 2026
- CVE-2024-2219735Monitor
Authenticated (user role) remote command execution by modifying `nginx` settings (GHSL-2023-269)
HighCVSS 8.8No exploitEPSS 2%nginxui · nginx uiJan 11, 2024
- CVE-2024-2382835Monitor
Nginx-UI authenticated RCE through injecting into the application config via CRLF
HighCVSS 8.8No exploitEPSS 1%nginxui · nginx uiJan 29, 2024
- CVE-2026-3303134Monitor
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens
HighCVSS 8.6No exploitEPSS 0%nginxui · nginx uiApr 20, 2026
- CVE-2024-4936630Monitor
Nginx UI's json field can construct a directory traversal payload, causing arbitrary files to be written
HighCVSS 7.7No exploitEPSS 1%nginxui · nginx uiOct 21, 2024
- CVE-2026-3302828Monitor
Nginx UI: Race Condition Leads to Persistent Data Corruption and Service Collapse
HighCVSS 7.1No exploitEPSS 1%nginxui · nginx uiMar 30, 2026
- CVE-2026-3302727Monitor
Nginx UI: Improper Path Validation Allows Recursive Deletion of the Nginx Configuration Directory
MediumCVSS 6.9No exploitEPSS 1%nginxui · nginx uiMar 30, 2026
- CVE-2026-3302927Monitor
Nginx UI: DoS via Negative Integer Input in Logrotate Interval
MediumCVSS 6.9No exploitEPSS 0%nginxui · nginx uiMar 30, 2026
- CVE-2024-2219626Monitor
Authenticated (user role) SQL injection in `OrderAndPaginate` (GHSL-2023-270)
MediumCVSS 6.5No exploitEPSS 1%nginxui · nginx uiJan 11, 2024
- CVE-2026-4222326Monitor
nginx-ui: Settings API Exposes Protected Secrets
MediumCVSS 6.5No exploitEPSS 0%nginxui · nginx uiMay 4, 2026
- CVE-2026-4222026Monitor
nginx-ui: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui s
MediumCVSS 6.5No exploitEPSS 0%nginxui · nginx uiMay 4, 2026
- CVE-2024-4936722Monitor
Nginx UI's log path can be controlled
MediumCVSS 5.5No exploitEPSS 1%nginxui · nginx uiOct 21, 2024
- CVE-2026-3440322Monitor
Nginx-UI vulnerable to Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints
MediumCVSS 5.5No exploitEPSS 0%nginxui · nginx uiApr 20, 2026