Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI
Modified: 6/25/2026
package
pkg:go/github.com/0xJacky/Nginx-UI
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI
Modified: 6/25/2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI
Modified: 6/25/2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints
Modified: 6/25/2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback
Modified: 7/21/2026
Authenticated (user role) arbitrary command execution by modifying `start_cmd` setting (GHSL-2023-268)
Modified: 7/6/2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval
Modified: 9/10/2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups
Modified: 7/6/2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure
Modified: 3/23/2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim
Modified: 6/25/2026
Authenticated (user role) SQL injection in `OrderAndPaginate` (GHSL-2023-270)
Modified: 7/6/2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover
Modified: 9/10/2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse
Modified: 9/10/2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation
Modified: 9/10/2026
Authenticated (user role) remote command execution by modifying `nginx` settings (GHSL-2023-269)
Modified: 7/6/2026
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF
Modified: 7/6/2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services
Modified: 6/25/2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens
Modified: 6/25/2026
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature
Modified: 7/6/2026
Arbitrary command execution in github.com/0xJacky/Nginx-UI
Modified: 5/20/2024
SQL injection in github.com/0xJacky/Nginx-UI
Modified: 5/20/2024
Remote command execution in github.com/0xJacky/Nginx-UI
Modified: 5/20/2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI
Modified: 7/9/2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI
Modified: 7/9/2024
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI
Modified: 3/23/2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI
Modified: 4/2/2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI
Modified: 4/2/2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI
Modified: 4/2/2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI
Modified: 4/2/2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI
Modified: 4/2/2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI
Modified: 6/25/2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI
Modified: 6/25/2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI
Modified: 6/25/2026