Vulnerability index

Browse CVEs

23 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-0765 Open WebUI PIP install_frontmatter_requirements Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to … Open Webui Mitigation only Fix from $1,9502026-01-23 HIGH 8.8 CVE-2026-0766EPSS 27% Open WebUI load_tool_module_by_id Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitr… Open Webui Mitigation only Fix from $1,9502026-01-23 MEDIUM 6.5 CVE-2026-0767 Open WebUI Cleartext Transmission of Credentials Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclo… Open Webui Mitigation only Fix from $1,6002026-01-23 HIGH 8.2 CVE-2024-8053 In version v0.3.10 of open-webui/open-webui, the `api/v1/utils/pdf` endpoint lacks authentication mechanisms, allowing unauthenticated attackers to a… Open Webui No fix yet Fix from $1,9502025-03-20 HIGH 8.4 CVE-2024-7990 A stored cross-site scripting (XSS) vulnerability exists in open-webui/open-webui version 0.3.8. The vulnerability is present in the `/api/v1/models/… Open Webui No fix yet Fix from $1,9502025-03-20 HIGH 7.7 CVE-2024-7959 The `/openai/models` endpoint in open-webui/open-webui version 0.3.8 is vulnerable to Server-Side Request Forgery (SSRF). An attacker can change the … Open Webui No fix yet Fix from $1,9502025-03-20 HIGH 7.5 CVE-2024-7983 In version 0.3.8 of open-webui, an endpoint for converting markdown to HTML is exposed without authentication. A maliciously crafted markdown payload… Open Webui No fix yet Fix from $1,9502025-03-20 CRITICAL 9.0 CVE-2024-7053 A vulnerability in open-webui/open-webui version 0.3.8 allows an attacker with a user-level account to perform a session fixation attack. The session… Open Webui No fix yet Fix from $2,3002025-03-20 HIGH 8.9 CVE-2024-7044 A Stored Cross-Site Scripting (XSS) vulnerability exists in the chat file upload functionality of open-webui/open-webui version 0.3.8. An attacker ca… Open Webui No fix yet Fix from $1,9502025-03-20 HIGH 8.8 CVE-2024-7043 An improper access control vulnerability in open-webui/open-webui v0.3.8 allows attackers to view and delete any files. The application does not veri… Open Webui No fix yet Fix from $1,9502025-03-20 HIGH 7.5 CVE-2024-7036 A vulnerability in open-webui/open-webui v0.3.8 allows an unauthenticated attacker to sign up with excessively large text in the 'name' field, causin… Open Webui No fix yet Fix from $1,9502025-03-20 HIGH 7.2 CVE-2024-7034 In open-webui version 0.3.8, the endpoint `/models/upload` is vulnerable to arbitrary file write due to improper handling of user-supplied filenames.… Open Webui No fix yet Fix from $1,9502025-03-20 MEDIUM 6.9 CVE-2024-7035 In version v0.3.8 of open-webui/open-webui, sensitive actions such as deleting and resetting are performed using the GET method. This vulnerability a… Open Webui No fix yet Fix from $1,6002025-03-20 MEDIUM 6.7 CVE-2024-7039 In open-webui/open-webui version v0.3.8, there is an improper privilege management vulnerability. The application allows an attacker, acting as an ad… Open Webui No fix yet Fix from $1,6002025-03-20 HIGH 7.2 CVE-2024-7033 In version 0.3.8 of open-webui/open-webui, an arbitrary file write vulnerability exists in the download_model endpoint. When deployed on Windows, the… Open Webui No fix yet Fix from $1,9502025-03-20 HIGH 7.5 CVE-2024-12534 In version v0.3.32 of open-webui/open-webui, the application allows users to submit large payloads in the email and password fields during the sign-i… Open Webui No fix yet Fix from $1,9502025-03-20 HIGH 7.5 CVE-2024-12537 In version 0.3.32 of open-webui/open-webui, the absence of authentication mechanisms allows any unauthenticated attacker to access the `api/v1/utils/… Open Webui No fix yet Fix from $1,9502025-03-20 MEDIUM 5.4 CVE-2024-7049 In version v0.3.8 of open-webui/open-webui, a vulnerability exists where a token is returned when a user with a pending role logs in. This allows the… Open Webui No fix yet Fix from $1,6002024-10-10 MEDIUM 5.4 CVE-2024-7048 In version v0.3.8 of open-webui, an improper privilege management vulnerability exists in the API endpoints GET /api/v1/documents/ and POST /rag/api/… Open Webui No fix yet Fix from $1,6002024-10-10 HIGH 7.2 CVE-2024-7037 In version v0.3.8 of open-webui/open-webui, the endpoint /api/pipelines/upload is vulnerable to arbitrary file write and delete due to unsanitized fi… Open Webui No fix yet Fix from $1,9502024-10-09 MEDIUM 6.5 CVE-2024-7041 An Insecure Direct Object Reference (IDOR) vulnerability exists in open-webui/open-webui version v0.3.8. The vulnerability occurs in the API endpoint… Open Webui No fix yet Fix from $1,6002024-10-09 HIGH 8.8 CVE-2024-6707 Attacker controlled files can be uploaded to arbitrary locations on the web server's filesystem by abusing a path traversal vulnerability. Open Webui No fix yet Fix from $1,9502024-08-07 MEDIUM 6.1 CVE-2024-6706 Attackers can craft a malicious prompt that coerces the language model into executing arbitrary JavaScript in the context of the web page. Open Webui No fix yet Fix from $1,6002024-08-07