docker vulnerability? nginx/php dockers

Hey i am trying to give people web hosting on my server. How secure is it to just give them access to a docker that runs nginx and php this docker is also running its own sftp client. Is there any way they can affect the host machine? If so are there any practices i can go apon to prevent abuse?

