Nginxproxymanager Nginx Proxy Manager
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Nginxproxymanager Nginx Proxy Manager.
By the Year
In 2026 there have been 2 vulnerabilities in Nginxproxymanager Nginx Proxy Manager with an average score of 7.2 out of ten. Nginx Proxy Manager did not have any published security vulnerabilities last year. That is, 2 more vulnerabilities have already been reported in 2026 as compared to last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 2 | 7.20 |
| 2025 | 0 | 0.00 |
| 2024 | 0 | 0.00 |
| 2023 | 0 | 0.00 |
| 2022 | 1 | 4.80 |
It may take a day or so for new Nginx Proxy Manager vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Nginxproxymanager Nginx Proxy Manager Security Vulnerabilities
NginxProxyManager NGPM <=2.15.1 Auth Bypass via intCert.validate (VRoute)
CVE-2026-93964
6.9 - Medium
- September 20, 2026
A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCertificate.validate of the file backend/internal/certificate.js of the component Validate Route. The manipulation results in missing authentication. The attack can be launched remotely. The exploit is now public and may be used. Endpoint only processes and echoes back the certificate the caller submits (no stored data leaked); the real risk is unauthenticated openssl processing of attacker input. The project was informed of the problem early through an issue report but has not responded yet.
Missing Authentication for Critical Function
Nginx Proxy Manager RCE via OS CLI Injection 2.9.14-2.15.1
CVE-2026-40519
7.5 - High
- June 08, 2026
Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticated remote code execution vulnerability via OS command injection in the setupCertbotPlugins() function in backend/setup.js, allowing attackers with certificates:manage permission to execute arbitrary commands by storing a malicious payload in the dns_provider_credentials field. The user-controlled dns_provider_credentials value is interpolated directly into a shell command executed via child_process.exec() without sanitization or escaping, causing the injected command to execute upon backend restart.
Shell injection
jc21.com Nginx Proxy Manager before 2.9.17
CVE-2022-28379
4.8 - Medium
- April 03, 2022
jc21.com Nginx Proxy Manager before 2.9.17 allows XSS during item deletion.
XSS
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Nginxproxymanager Nginx Proxy Manager or by Nginxproxymanager? Click the Watch button to subscribe.