CVE-2023-27224: JC21 Nginx Proxy Manager

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

An issue found in NginxProxyManager v.2.9.19 allows an attacker to execute arbitrary code via a lua script to the configuration file.

Affected products

  • JC21 Nginx Proxy Manager: version 2.9.19 only

Published 2023-03-22. Last modified 2026-06-17.