Vulnerability index

Browse CVEs

116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Open Webui MEDIUM 5.4
CVE-2025-64495

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. In versions 0.6.34 and below, the functionality th…

Fix: 0.6.35+
Fix from $1,600 2025-11-08
Open Webui MEDIUM 5.4
CVE-2025-46571

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6.6, low privileged users can u…

Fix: 0.6.6+
Fix from $1,600 2025-05-05
Open Webui MEDIUM 5.4
CVE-2025-46719

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6.6, a vulnerability in the way…

Fix: 0.6.6+
Fix from $1,600 2025-05-05
Open Webui HIGH 8.2
CVE-2024-8053

In version v0.3.10 of open-webui/open-webui, the `api/v1/utils/pdf` endpoint lacks authentication mechanisms, allowing unauthenticated attackers to a…

No fix yet
Fix from $1,950 2025-03-20
Open Webui CRITICAL 9.0
CVE-2024-8017

An XSS vulnerability exists in open-webui/open-webui versions <= 0.3.8, specifically in the function that constructs the HTML for tooltips. This vuln…

Fix: after 0.3.8
Fix from $2,300 2025-03-20
Open Webui HIGH 8.4
CVE-2024-7990

A stored cross-site scripting (XSS) vulnerability exists in open-webui/open-webui version 0.3.8. The vulnerability is present in the `/api/v1/models/…

No fix yet
Fix from $1,950 2025-03-20
Open Webui HIGH 7.7
CVE-2024-7959

The `/openai/models` endpoint in open-webui/open-webui version 0.3.8 is vulnerable to Server-Side Request Forgery (SSRF). An attacker can change the …

No fix yet
Fix from $1,950 2025-03-20
Open Webui HIGH 7.5
CVE-2024-7983

In version 0.3.8 of open-webui, an endpoint for converting markdown to HTML is exposed without authentication. A maliciously crafted markdown payload…

No fix yet
Fix from $1,950 2025-03-20
Open Webui HIGH 8.8
CVE-2024-7806

A vulnerability in open-webui/open-webui versions <= 0.3.8 allows remote code execution by non-admin users via Cross-Site Request Forgery (CSRF). The…

Fix: after 0.3.8
Fix from $1,950 2025-03-20
Open Webui CRITICAL 9.0
CVE-2024-7053

A vulnerability in open-webui/open-webui version 0.3.8 allows an attacker with a user-level account to perform a session fixation attack. The session…

No fix yet
Fix from $2,300 2025-03-20
Open Webui HIGH 8.9
CVE-2024-7044

A Stored Cross-Site Scripting (XSS) vulnerability exists in the chat file upload functionality of open-webui/open-webui version 0.3.8. An attacker ca…

No fix yet
Fix from $1,950 2025-03-20
Open Webui HIGH 8.8
CVE-2024-7043

An improper access control vulnerability in open-webui/open-webui v0.3.8 allows attackers to view and delete any files. The application does not veri…

No fix yet
Fix from $1,950 2025-03-20
Open Webui HIGH 7.5
CVE-2024-7036

A vulnerability in open-webui/open-webui v0.3.8 allows an unauthenticated attacker to sign up with excessively large text in the 'name' field, causin…

No fix yet
Fix from $1,950 2025-03-20
Open Webui HIGH 7.2
CVE-2024-7034

In open-webui version 0.3.8, the endpoint `/models/upload` is vulnerable to arbitrary file write due to improper handling of user-supplied filenames.…

No fix yet
Fix from $1,950 2025-03-20
Open Webui MEDIUM 6.9
CVE-2024-7035

In version v0.3.8 of open-webui/open-webui, sensitive actions such as deleting and resetting are performed using the GET method. This vulnerability a…

No fix yet
Fix from $1,600 2025-03-20
Open Webui MEDIUM 6.7
CVE-2024-7039

In open-webui/open-webui version v0.3.8, there is an improper privilege management vulnerability. The application allows an attacker, acting as an ad…

No fix yet
Fix from $1,600 2025-03-20
Open Webui HIGH 7.2
CVE-2024-7033

In version 0.3.8 of open-webui/open-webui, an arbitrary file write vulnerability exists in the download_model endpoint. When deployed on Windows, the…

No fix yet
Fix from $1,950 2025-03-20
Open Webui HIGH 7.5
CVE-2024-12534

In version v0.3.32 of open-webui/open-webui, the application allows users to submit large payloads in the email and password fields during the sign-i…

No fix yet
Fix from $1,950 2025-03-20
Open Webui HIGH 7.5
CVE-2024-12537

In version 0.3.32 of open-webui/open-webui, the absence of authentication mechanisms allows any unauthenticated attacker to access the `api/v1/utils/…

No fix yet
Fix from $1,950 2025-03-20
Open Webui MEDIUM 5.4
CVE-2024-7049

In version v0.3.8 of open-webui/open-webui, a vulnerability exists where a token is returned when a user with a pending role logs in. This allows the…

No fix yet
Fix from $1,600 2024-10-10
Open Webui MEDIUM 5.4
CVE-2024-7048

In version v0.3.8 of open-webui, an improper privilege management vulnerability exists in the API endpoints GET /api/v1/documents/ and POST /rag/api/…

No fix yet
Fix from $1,600 2024-10-10
Open Webui HIGH 7.2
CVE-2024-7037

In version v0.3.8 of open-webui/open-webui, the endpoint /api/pipelines/upload is vulnerable to arbitrary file write and delete due to unsanitized fi…

No fix yet
Fix from $1,950 2024-10-09
Open Webui MEDIUM 6.5
CVE-2024-7041

An Insecure Direct Object Reference (IDOR) vulnerability exists in open-webui/open-webui version v0.3.8. The vulnerability occurs in the API endpoint…

No fix yet
Fix from $1,600 2024-10-09
Open Webui HIGH 8.8
CVE-2024-6707

Attacker controlled files can be uploaded to arbitrary locations on the web server's filesystem by abusing a path traversal vulnerability.

No fix yet
Fix from $1,950 2024-08-07
Open Webui MEDIUM 6.1
CVE-2024-6706

Attackers can craft a malicious prompt that coerces the language model into executing arbitrary JavaScript in the context of the web page.

No fix yet
Fix from $1,600 2024-08-07
Open Webui MEDIUM 6.4
CVE-2024-30256

Open WebUI is a user-friendly WebUI for LLMs. Open-webui is vulnerable to authenticated blind server-side request forgery. This vulnerability is fixe…

Fix: 0.1.117+
Fix from $1,600 2024-04-16