Vendor
Nginx Proxy Manager versions 2.16.0 and earlier lack rate-limiting on authentication endpoints, enabling unauthenticated attackers to perform credential stuffing and bypass MFA via brute-force.