threat
engine
.sh
Back
·
··:··
Home
/
Product
/
jc21 nginx proxy manager
Product
jc21 nginx proxy manager
8 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2025-50579
all versions
A CORS misconfiguration in Nginx Proxy Manager v2.12.3 allows unauthorized domains to access sensitive data, particularly JWT toke
5.3
MEDIUM
CVE-2024-46257
all versions
A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacker to achie
6.3
MEDIUM
CVE-2024-46256
all versions
A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add Let's Enc
9.8
CRITICAL
CVE-2024-39935
< 2.11.3
jc21 NGINX Proxy Manager before 2.11.3 allows backend/internal/certificate.js OS command injection by an authenticated user (with
8.8
HIGH
CVE-2023-27224
all versions
An issue found in NginxProxyManager v.2.9.19 allows an attacker to execute arbitrary code via a lua script to the configuration fi
9.8
CRITICAL
CVE-2023-23596
<= 2.9.19
jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection. When creating an access list, the backend builds an htpasswd
8.8
HIGH
CVE-2022-28379
< 2.9.17
jc21.com Nginx Proxy Manager before 2.9.17 allows XSS during item deletion.
6.8
MEDIUM
CVE-2019-15517
< 2.0.13
jc21 Nginx Proxy Manager before 2.0.13 allows %2e%2e%2f directory traversal.
5.5
MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin