Nginxproxymanager

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 6
    Known Exploited: 0
    1
    Critical Level Threats
    1
    High Level Threats
    4
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-50892

    Incorrect access control in the "Let's Encrypt" certificate download endpoint of Nginx Proxy Manager v2.14.0 allows authenticated attackers to obtain the TLS private key material via a crafted GET request.

    Last Modified: Jun 19, 2026
    Published: Jun 15, 2026

    CVE-2026-40519

    Nginx Proxy Manager Authenticated RCE via setupCertbotPlugins()

    Last Modified: Jul 14, 2026
    Published: Jun 08, 2026

    CVE-2025-50579

    A CORS misconfiguration in Nginx Proxy Manager v2.12.3 allows unauthorized domains to access sensitive data, particularly JWT tokens, due to improper validation of the Origin header. This misconfiguration enables attackers to intercept tokens using a simple browser script and exfiltrate them to a remote attacker-controlled server, potentially leading to unauthorized actions within the application.

    Last Modified: Sep 24, 2025
    Published: Aug 19, 2025

    CVE-2024-46256

    A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add Let's Encrypt Certificate.

    Last Modified: Jun 03, 2025
    Published: Sep 27, 2024

    CVE-2024-46257

    A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacker to achieve remote code execution via Add Let's Encrypt Certificate. NOTE: this is not part of any NGINX software shipped by F5.

    Last Modified: Jun 03, 2025
    Published: Sep 27, 2024
    Items Per Page
    Nginxproxymanager Vulnerabilities & Security CVEs | CVE-DB