Nginx UI
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 8 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from April 20, 2026 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Nginx UI: Backup restore follows crafted symlinks into the live Nginx configuration path before restore flags are applied
Nginx UI: Authentication bypass: password login does not enforce a passkey-only second factor (2FA bypass)
Nginx UI: Node Secret Credential Exposure via URL Query Parameter
Nginx UI: Unauthenticated signed-request body staging can exhaust temporary storage
Nginx UI: Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware Allows Access to Internal Services
nginx-ui: Settings API Exposes Protected Secrets
nginx-ui: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim
Nginx-UI vulnerable to Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints
Monitor Nginx UI in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.