Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

roxy-wi — Vulnerabilities & Security Advisories 23

Browse all 23 CVE security advisories affecting roxy-wi. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Roxy-WI is a web interface for managing HAProxy, Nginx, and Keepalived, primarily used for load balancer configuration and monitoring. Historically, it has been vulnerable to multiple security issues including remote code execution (RCE), cross-site scripting (XSS), and privilege escalation vulnerabilities. The application has accumulated 9 CVEs to date, with several allowing unauthenticated attackers to execute arbitrary commands or bypass security controls. Notable characteristics include its exposure of sensitive system information and insufficient input validation in multiple components. While no major public incidents have been widely documented, the consistent discovery of critical vulnerabilities in its codebase highlights ongoing security concerns for administrators deploying this tool in production environments.

Top products by roxy-wi: roxy-wi
CVE ID Title CVSS Severity Published
CVE-2026-45569 Roxy-WI: Path-traversal patch in commit d4d10006 is a no-op (tuple-membership bug) — roxy-wi CWE-22 8.1 High 2026-06-10
CVE-2026-45567 Roxy-WI: Authentication bypass via 'api' substring in URL + unauthenticated /api/gpt — roxy-wi CWE-287 8.3 High 2026-06-10
CVE-2026-45566 Roxy-WI: Open redirect on /login?next= via basic-auth userinfo syntax bypass — roxy-wi CWE-601 6.1 Medium 2026-06-10
CVE-2026-45565 Roxy-WI: EscapedString validator skips its '..' block when stripping (root cause for several path-traversal/RCE vectors) — roxy-wi CWE-20 8.1 High 2026-06-10
CVE-2026-45564 Roxy-WI: Authenticated RCE via 'configver' URL parameter (os.system sink in /config/versions/.../save) — roxy-wi CWE-78 8.8 High 2026-06-10
CVE-2026-45563 Roxy-WI: IDOR — any authenticated user can read another user's full action history — roxy-wi CWE-639 4.3 Medium 2026-06-10
CVE-2026-45561 Roxy-WI: SSRF in /smon/agent/<endpoint>/<server_ip> reachable to cloud metadata IPs — roxy-wi CWE-918 6.5 Medium 2026-06-10
CVE-2026-45560 Roxy-WI: Stored XSS in log viewer (wrap_line/highlight_word produce unescaped HTML) — roxy-wi CWE-79 6.1 Medium 2026-06-10
CVE-2026-45559 Roxy-WI: LDAP injection in /user/ldap/<username> (admin-only) — roxy-wi CWE-90 4.9 Medium 2026-06-10
CVE-2026-45558 Roxy-WI: Authenticated RCE on every managed HAProxy load balancer via `option` field config injection in section save — roxy-wi CWE-20 9.9 Critical 2026-06-10
CVE-2026-45556 Roxy-WI: Authenticated arbitrary file write on every managed load balancer (and downstream RCE) via WAF rule save `config_file_name` — roxy-wi CWE-20 9.9 Critical 2026-06-10
CVE-2026-45550 Roxy-WI: IDOR on PUT /smon/check — any user can rewrite any tenant's monitoring URL/IP/body — roxy-wi CWE-639 9.1 Critical 2026-06-10
CVE-2026-45549 Roxy-WI: Authorization bypass on POST /smon/agent/action/<action> — guest can stop or restart smon-agent on any host — roxy-wi CWE-862 8.5 High 2026-06-10
CVE-2026-45552 Roxy-WI: Cross-tenant authorization bypass on /install/* — guest can run Ansible / SSH on every registered server — roxy-wi CWE-639 9.9 Critical 2026-06-10
CVE-2026-33208 Roxy-WI Vulnerable to Authenticated Remote Code Execution via OS Command Injection in find-in-config Endpoint — roxy-wi CWE-78 8.8AI High AI 2026-04-24
CVE-2026-33078 Roxy-WI has SQL Injection in haproxy_section_save Endpoint via Unsanitized server_ip Parameter — roxy-wi CWE-89 9.8AI Critical AI 2026-04-24
CVE-2026-33077 Roxy-WI has an arbitrary file read vulnerability — roxy-wi CWE-22 7.5AI High AI 2026-04-24
CVE-2026-33076 Roxy-WI vulnerable to path traversal and arbitrary file writing — roxy-wi CWE-22 9.8AI Critical AI 2026-04-24
CVE-2026-33432 Roxy-WI has Pre-Authentication LDAP Injection that Leads to Authentication Bypass — roxy-wi CWE-287 7.5AI High AI 2026-04-20
CVE-2026-33431 Roxy-WI Vulnerable to Authenticated Arbitrary File Read via Path Traversal in Config Version Viewer — roxy-wi CWE-24 8.1AI High AI 2026-04-20
CVE-2026-27811 Roxy-WI has a Command Injection via diff parameter in config comparison allows authenticated RCE — roxy-wi CWE-77 8.8 High 2026-03-17
CVE-2026-22265 Roxy-WI has a Command Injection via grep parameter in logs.py allows authenticated RCE — roxy-wi CWE-78 7.5 High 2026-01-15
CVE-2024-43804 OS Command Injection via Port Scan Functionality in Roxy-WI — roxy-wi CWE-78 8.8 High 2024-08-29

This page lists every published CVE security advisory associated with roxy-wi. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.