Jc21 maintains Nginx Proxy Manager, a narrowly scoped reverse-proxy application that, despite modest volume, occupies a prominent position in deployment due to its role as an internet-facing access gateway. Vulnerabilities affecting this vendor skew strongly toward critical severity and recur through high-impact weakness classes including command injection, OS command injection, path traversal, and SQL injection—flaws that reflect the application's need to parse and forward network requests while managing access control. Defenders should treat updates for this product as high-priority given its exposure tier and severity profile; current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jc21 over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-23596HIGH jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection. When creating an access list, the backend builds an htpasswd file with crafted username and/or password input t | Jan 20, 2023 | 8.8 | 35 | NO | NO |
CVE-2024-46256CRITICAL A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add Let's Encrypt Certificate. | Sep 27, 2024 | 9.8 | 31 | NO | NO |
CVE-2023-27224CRITICAL An issue found in NginxProxyManager v.2.9.19 allows an attacker to execute arbitrary code via a lua script to the configuration file. | Mar 22, 2023 | 9.8 | 29 | NO | NO |
CVE-2024-39935HIGH jc21 NGINX Proxy Manager before 2.11.3 allows backend/internal/certificate.js OS command injection by an authenticated user (with certificate management privileges) via untrusted i | Jul 4, 2024 | 8.8 | 24 | NO | NO |
CVE-2025-50579MEDIUM A CORS misconfiguration in Nginx Proxy Manager v2.12.3 allows unauthorized domains to access sensitive data, particularly JWT tokens, due to improper validation of the Origin heade | Aug 19, 2025 | 5.3 | 20 | NO | NO |
CVE-2024-46257MEDIUM A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacker to achieve remote code execution via Add Let's Encrypt Cer | Sep 27, 2024 | 6.3 | 20 | NO | NO |
CVE-2019-15517MEDIUM jc21 Nginx Proxy Manager before 2.0.13 allows %2e%2e%2f directory traversal. | Aug 23, 2019 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jc21.
Media articles that mention a CVE ID that affects a product developed by Jc21 — matched by CVE ID, not by vendor name.