CVE Tools

Nginxui

5 CVEs tracked since 2024. Since Jan 2024, none of them reached CISA KEV.

Nginxui CVEs per month

Jan 2024 to Jan 2024. Point at a month, or focus the strip and use the arrow keys.
Nginxui CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2024-0150

Products

The products that kept showing up in Nginxui's monthly top three, with their CVEs summed over those months.

  1. NGINX Ui51 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Nginxui.

  1. CVE-2026-44015Nginx UI: Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware Allows Access to Internal Services8.5
  2. CVE-2026-42238Unauthenticated Remote Code Execution via Backup Restore in nginx-ui9.8
  3. CVE-2026-42223nginx-ui: Settings API Exposes Protected Secrets6.5
  4. CVE-2026-42222nginx-ui: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover8.1
  5. CVE-2026-42221nginx-ui: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim8.1
  6. CVE-2026-42220nginx-ui: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback6.5
  7. CVE-2026-34403Nginx-UI vulnerable to Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints8.1
  8. CVE-2026-33031Nginx-UI: Disabled users retain full API access through previously issued bearer tokens8.1
  9. CVE-2026-33026nginx-ui Backup Restore Allows Tampering with Encrypted Backups9.1
  10. CVE-2026-33027Nginx UI: Improper Path Validation Allows Recursive Deletion of the Nginx Configuration Directory6.5
  11. CVE-2026-33028Nginx UI: Race Condition Leads to Persistent Data Corruption and Service Collapse7.5
  12. CVE-2026-33029Nginx UI: DoS via Negative Integer Input in Logrotate Interval6.5
  13. CVE-2026-33030Nginx UI: Unencrypted Storage of DNS API Tokens and ACME Private Keys8.8
  14. CVE-2026-33032Nginx UI: Unauthenticated MCP Endpoint Allows Remote Nginx Takeover9.8
  15. CVE-2024-49368Unchecked logrotate settings lead to arbitrary command execution9.8

The record

Peak rank
#150 in Jan 2024
Busiest month shown
Jan 2024, 5 CVEs
Months with a KEV entry
0 since Jan 2024
Monthly snapshots
1 since 2024
Nginxui's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store