Skip to content
Noroxi

nginxui records

23 published records for vendor nginxui.

All records

23 records
  • Unchecked logrotate settings lead to arbitrary command execution

    HighCVSS 8.9Proof of conceptEPSS 28%

    nginxui · nginx uiOct 21, 2024

  • Nginx UI: Unauthenticated MCP Endpoint Allows Remote Nginx Takeover

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    nginxui · nginx uiMar 30, 2026

  • nginx-ui: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim

    CriticalCVSS 9.8Proof of conceptEPSS 2%

    nginxui · nginx uiMay 4, 2026

  • Nginx UI: Unauthenticated Backup Download with Encryption Key Disclosure

    CriticalCVSS 9.8Proof of conceptEPSS 1%

    nginxui · nginx uiMar 5, 2026

  • Nginx-UI arbitrary file write through the Import Certificate feature

    CriticalCVSS 9.8No exploitEPSS 1%

    nginxui · nginx uiJan 29, 2024

  • nginx-ui: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover

    CriticalCVSS 9.8No exploitEPSS 0%

    nginxui · nginx uiMay 4, 2026

  • Nginx UI: Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware Allows Access to Internal Services

    CriticalCVSS 9.9No exploitEPSS 0%

    nginxui · nginx uiMay 12, 2026

  • Nginx UI: Unencrypted Storage of DNS API Tokens and ACME Private Keys

    CriticalCVSS 9.9No exploitEPSS 0%

    nginxui · nginx uiMar 30, 2026

  • nginx-ui Backup Restore Allows Tampering with Encrypted Backups

    CriticalCVSS 9.4No exploitEPSS 0%

    nginxui · nginx uiMar 30, 2026

  • Authenticated (user role) arbitrary command execution by modifying `start_cmd` setting (GHSL-2023-268)

    HighCVSS 8.8Proof of conceptEPSS 4%

    nginxui · nginx uiJan 11, 2024

  • Unauthenticated Remote Code Execution via Backup Restore in nginx-ui

    CriticalCVSS 9.0No exploitEPSS 1%

    nginxui · nginx uiMay 4, 2026

  • Authenticated (user role) remote command execution by modifying `nginx` settings (GHSL-2023-269)

    HighCVSS 8.8No exploitEPSS 2%

    nginxui · nginx uiJan 11, 2024

  • Nginx-UI authenticated RCE through injecting into the application config via CRLF

    HighCVSS 8.8No exploitEPSS 1%

    nginxui · nginx uiJan 29, 2024

  • Nginx-UI: Disabled users retain full API access through previously issued bearer tokens

    HighCVSS 8.6No exploitEPSS 0%

    nginxui · nginx uiApr 20, 2026

  • Nginx UI's json field can construct a directory traversal payload, causing arbitrary files to be written

    HighCVSS 7.7No exploitEPSS 1%

    nginxui · nginx uiOct 21, 2024

  • Nginx UI: Race Condition Leads to Persistent Data Corruption and Service Collapse

    HighCVSS 7.1No exploitEPSS 1%

    nginxui · nginx uiMar 30, 2026

  • Nginx UI: Improper Path Validation Allows Recursive Deletion of the Nginx Configuration Directory

    MediumCVSS 6.9No exploitEPSS 1%

    nginxui · nginx uiMar 30, 2026

  • Nginx UI: DoS via Negative Integer Input in Logrotate Interval

    MediumCVSS 6.9No exploitEPSS 0%

    nginxui · nginx uiMar 30, 2026

  • Authenticated (user role) SQL injection in `OrderAndPaginate` (GHSL-2023-270)

    MediumCVSS 6.5No exploitEPSS 1%

    nginxui · nginx uiJan 11, 2024

  • nginx-ui: Settings API Exposes Protected Secrets

    MediumCVSS 6.5No exploitEPSS 0%

    nginxui · nginx uiMay 4, 2026

  • nginx-ui: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui s

    MediumCVSS 6.5No exploitEPSS 0%

    nginxui · nginx uiMay 4, 2026

  • Nginx UI's log path can be controlled

    MediumCVSS 5.5No exploitEPSS 1%

    nginxui · nginx uiOct 21, 2024

  • Nginx-UI vulnerable to Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints

    MediumCVSS 5.5No exploitEPSS 0%

    nginxui · nginx uiApr 20, 2026