Vulnerability index

Browse CVEs

116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Open Webui HIGH 8.1
CVE-2026-45675

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the LDAP and OAuth authentication …

Fix: 0.9.0+
Fix from $1,950 2026-05-15
Open Webui HIGH 8.0
CVE-2026-45671

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, any authenticated user can permane…

Fix: 0.9.0+
Fix from $1,950 2026-05-15
Open Webui HIGH 8.5
CVE-2026-45331

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, validate_url() in backend/open_web…

Fix: 0.9.0+
Fix from $1,950 2026-05-15
Open Webui HIGH 7.1
CVE-2026-45349

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, a user just needs to use the API e…

Fix: 0.9.0+
Fix from $1,950 2026-05-15
Open Webui HIGH 7.1
CVE-2026-45399

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, any authenticated user with low pr…

Fix: 0.9.0+
Fix from $1,950 2026-05-15
Open Webui MEDIUM 6.5
CVE-2026-45339

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, Open WebUI allows admins to restri…

Fix: 0.9.0+
Fix from $1,600 2026-05-15
Open Webui MEDIUM 5.4
CVE-2026-44563

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the /api/generate, /api/embed, /ap…

Fix: 0.9.0+
Fix from $1,600 2026-05-15
Open Webui MEDIUM 5.4
CVE-2026-44564

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the ydoc:document:update Socket.IO…

Fix: 0.9.0+
Fix from $1,600 2026-05-15
Open Webui HIGH 7.1
CVE-2026-44556

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the /responses endpoint in the Ope…

Fix: 0.9.0+
Fix from $1,950 2026-05-15
Open Webui MEDIUM 6.5
CVE-2026-44560

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the type: "file" (non-full-context…

Fix: 0.9.0+
Fix from $1,600 2026-05-15
Open Webui MEDIUM 6.5
CVE-2026-44562

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the POST /api/v1/models/import end…

Fix: 0.9.0+
Fix from $1,600 2026-05-15
Open Webui MEDIUM 5.4
CVE-2026-44558

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the channel router does not call f…

Fix: 0.9.0+
Fix from $1,600 2026-05-15
Open Webui MEDIUM 5.4
CVE-2026-44561

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the is_user_channel_member functio…

Fix: 0.9.0+
Fix from $1,600 2026-05-15
Open Webui CRITICAL 9.1
CVE-2026-44551

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the LDAP authentication endpoint d…

Fix: 0.9.0+
Fix from $2,300 2026-05-15
Open Webui HIGH 8.7
CVE-2026-44552

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the tool_servers and terminal_serv…

Fix: 0.9.0+
Fix from $1,950 2026-05-15
Open Webui HIGH 8.1
CVE-2026-44553

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, administrative role changes and us…

Fix: 0.9.0+
Fix from $1,950 2026-05-15
Open Webui HIGH 8.1
CVE-2026-44554

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the POST /api/v1/retrieval/process…

Fix: 0.9.0+
Fix from $1,950 2026-05-15
Open Webui HIGH 7.6
CVE-2026-44555

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, Open WebUI supports model composit…

Fix: 0.9.0+
Fix from $1,950 2026-05-15
Open Webui MEDIUM 5.0
CVE-2026-44550

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, FolderForm uses model_config = Con…

Fix: 0.9.0+
Fix from $1,600 2026-05-15
Open Webui HIGH 7.7
CVE-2026-34222EPSS 5%

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.11, there is a broken access …

Fix: 0.8.11+
Fix from $1,950 2026-04-01
Open Webui HIGH 8.1
CVE-2026-29070

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.6, an access control check is…

Fix: 0.8.6+
Fix from $1,950 2026-03-27
Open Webui HIGH 7.1
CVE-2026-28788

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.6, any authenticated user can…

Fix: 0.8.6+
Fix from $1,950 2026-03-27
Open Webui MEDIUM 5.4
CVE-2026-26192

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.7.0, aanually modifying chat hi…

Fix: 0.7.0+
Fix from $1,600 2026-02-19
Open Webui MEDIUM 5.4
CVE-2026-26193

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6.44, aanually modifying chat h…

Fix: 0.6.44+
Fix from $1,600 2026-02-19
Open Webui HIGH 8.8
CVE-2026-0765

Open WebUI PIP install_frontmatter_requirements Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to …

Mitigation only
Fix from $1,950 2026-01-23
Open Webui HIGH 8.8
CVE-2026-0766EPSS 27%

Open WebUI load_tool_module_by_id Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2026-01-23
Open Webui MEDIUM 6.5
CVE-2026-0767

Open WebUI Cleartext Transmission of Credentials Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclo…

Mitigation only
Fix from $1,600 2026-01-23
Open Webui MEDIUM 5.4
CVE-2025-65959

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.37, a Stored XSS vulnerability was di…

Fix: 0.6.37+
Fix from $1,600 2025-12-04
Open Webui HIGH 7.1
CVE-2025-65958

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.37, a Server-Side Request Forgery (SS…

Fix: 0.6.37+
Fix from $1,950 2025-12-04
Open Webui HIGH 8.0
CVE-2025-64496EPSS 8%

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Versions 0.6.224 and prior contain a code injectio…

Fix: 0.6.35+
Fix from $1,950 2025-11-08