NginxUI
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 23 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from January 11, 2024 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Nginx UI: Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware Allows Access to Internal Services
Unauthenticated Remote Code Execution via Backup Restore in nginx-ui
nginx-ui: Settings API Exposes Protected Secrets
nginx-ui: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover
nginx-ui: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim
nginx-ui: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback
Nginx-UI vulnerable to Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens
Nginx UI: Unauthenticated MCP Endpoint Allows Remote Nginx Takeover
Nginx UI: Unencrypted Storage of DNS API Tokens and ACME Private Keys
Monitor NginxUI in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.