VendorsOpen WebUIopen_webuiall versions
Vulnerabilities

Open WebUI Open Webui

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

160CVEs
CVE-2026-45346
Open WebUI: Stored Cross-Site Scripting in SVG Renderer
Published 2026-05-15 · Analyzed
5.4EPSS 0.002
CVE-2026-45299
Open WebUI: Stored Cross-Site Scripting In Profile Picture
Published 2026-05-15 · Analyzed
5.4EPSS 0.002
CVE-2026-45397
Open WebUI: Unauthenticated RAG Configuration Disclosure
Published 2026-05-15 · Analyzed
5.3EPSS 0.008
CVE-2026-59218
Open WebUI: Account enumeration via observable login timing discrepancy
Published 2026-07-09 · Analyzed
5.3EPSS 0.004
CVE-2026-54022
Open WebUI: Any authenticated user can read other users' private notes via Socket.IO
Published 2026-06-23 · Analyzed
5.3EPSS 0.003
CVE-2026-88001
Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets
Published 2026-09-09 · Analyzed
5.0EPSS 0.004
CVE-2026-59213
Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)
Published 2026-07-09 · Analyzed
5.0EPSS 0.004
CVE-2026-44550
Open WebUI: Mass Assignment via Pydantic extra='allow' Allows Creating Folders in Other Users' Accounts
Published 2026-05-15 · Analyzed
5.0EPSS 0.003
CVE-2026-44568
Open WebUI: Stored XSS in Pending User Overlay via Incorrect DOMPurify Application Order
Published 2026-05-15 · Analyzed
4.8EPSS 0.003
CVE-2026-45317
Open WebUI: Cross-Site Request Forgery (CSRF) via Image URL Manipulation
Published 2026-05-15 · Analyzed
4.6EPSS 0.001
CVE-2026-59226
Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
Published 2026-07-09 · Analyzed
4.3EPSS 0.005
CVE-2026-87012
Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value
Published 2026-09-09 · Analyzed
4.3EPSS 0.005
CVE-2026-87013
Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle
Published 2026-09-09 · Analyzed
4.3EPSS 0.005
CVE-2026-70483
Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint
Published 2026-08-04 · Analyzed
4.3EPSS 0.005
CVE-2026-28786
Open WebUI vulnerable to Path Traversal in `POST /api/v1/audio/transcriptions`
Published 2026-03-26 · Analyzed
4.3EPSS 0.004
CVE-2026-59223
Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
Published 2026-07-09 · Analyzed
4.3EPSS 0.004
CVE-2026-87017
Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends
Published 2026-09-09 · Analyzed
4.3EPSS 0.004
CVE-2026-87994
Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint
Published 2026-09-09 · Analyzed
4.3EPSS 0.004
CVE-2026-87997
Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions
Published 2026-09-09 · Analyzed
4.3EPSS 0.004
CVE-2026-59217
Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
Published 2026-07-09 · Modified
4.3EPSS 0.004
CVE-2026-70488
Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup
Published 2026-08-04 · Analyzed
4.3EPSS 0.004
CVE-2026-54014
Open WebUI: Sibling-Prefix Path Traversal via /cache/{path} in open-webui/open-webui
Published 2026-06-23 · Analyzed
4.3EPSS 0.004
CVE-2026-45387
Open WebUI: Sharing models for others to use (read permission) also exposes model details (system prompt leakage)
Published 2026-05-15 · Analyzed
4.3EPSS 0.003
CVE-2026-34225
Open WebUI has Blind Server Side Request Forgery in its Image Edit Functionality
Published 2026-04-14 · Analyzed
4.3EPSS 0.003
CVE-2026-54016
Open WebUI: Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumeration
Published 2026-06-23 · Analyzed
4.3EPSS 0.003
CVE-2026-44557
Open WebUI: Global Knowledge Base Enumeration via knowledge-bases Meta-Collection
Published 2026-05-15 · Analyzed
4.3EPSS 0.003
CVE-2026-44559
Open WebUI: Missing Access Check on Channel Members Endpoint for Standard Channels
Published 2026-05-15 · Analyzed
4.3EPSS 0.003
CVE-2026-54006
Open WebUI: Calendar event re-parenting allows writing events into another user's calendar
Published 2026-06-23 · Analyzed
4.3EPSS 0.003
CVE-2026-45385
Open WebUI: An IDOR vulnerability exists in the update_message_by_id API endpoint
Published 2026-05-15 · Analyzed
4.3EPSS 0.003
CVE-2026-45386
Open WebUI: An IDOR vulnerability exists in the pin_channel_message API endpoint
Published 2026-05-15 · Modified
4.3EPSS 0.003
CVE-2025-63681
open-webui v0.6.33 is vulnerable to Incorrect Access Control. The API /api/tasks/stop/ directly accesses and cancels tasks without verifying user ownership, enabling attackers (a normal user) to stop arbitrary LLM response tasks.
Published 2025-12-04 · Modified
4.3EPSS 0.003
CVE-2026-29071
Open WebUI's Insecure Direct Object Reference (IDOR) allows access to other users' memories
Published 2026-03-26 · Analyzed
4.3EPSS 0.003
CVE-2026-70480
Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering
Published 2026-08-04 · Analyzed
4.1EPSS 0.003
CVE-2026-45316
Open WebUI: Read-Only Users Can Toggle Note Pin Status via Incorrect Permission Check (Write via Read-Only Access)
Published 2026-05-15 · Analyzed
3.5EPSS 0.003
CVE-2026-59215
Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding
Published 2026-07-09 · Analyzed
3.1EPSS 0.003
CVE-2026-0766
Open WebUI load_tool_module_by_id Command Injection Remote Code Execution Vulnerability
Published 2026-01-23 · Rejected
n/aEPSS 0.260
CVE-2026-0765
Open WebUI PIP install_frontmatter_requirements Command Injection Remote Code Execution Vulnerability
Published 2026-01-23 · Rejected
n/aEPSS 0.016
CVE-2024-7806
Remote Code Execution by Non-Admin Users via CSRF in open-webui/open-webui
Published 2025-03-20 · Rejected
n/aEPSS 0.005
CVE-2024-7049
Exposure of Token in open-webui/open-webui
Published 2024-10-10 · Rejected
n/aEPSS 0.003
CVE-2026-0767
Open WebUI Cleartext Transmission of Credentials Information Disclosure Vulnerability
Published 2026-01-23 · Rejected
n/aEPSS 0.003
← Prev4 / 4