Openwebui

Open Webui

142 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 2.86%
  • Veröffentlicht 26.03.2026 23:38:20
  • Zuletzt bearbeitet 01.04.2026 16:12:25

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.6, any authenticated user can overwrite any file's content by ID through the `POST /api/v1/retrieval/process/files/batch` endpoint...

Exploit
  • EPSS 0.43%
  • Veröffentlicht 26.03.2026 23:37:25
  • Zuletzt bearbeitet 30.03.2026 17:25:24

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.6, an unsanitized filename field in the speech-to-text transcription endpoint allows any authenticated non-admin user to trigger a...

Exploit
  • EPSS 0.19%
  • Veröffentlicht 19.02.2026 19:15:03
  • Zuletzt bearbeitet 20.02.2026 20:15:37

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6.44, aanually modifying chat history allows setting the `embeds` property on a response message, the content of which is loaded int...

Exploit
  • EPSS 0.19%
  • Veröffentlicht 19.02.2026 19:10:52
  • Zuletzt bearbeitet 20.02.2026 20:17:25

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.7.0, aanually modifying chat history allows setting the `html` property within document metadata. This causes the frontend to enter ...

  • EPSS 0.24%
  • Veröffentlicht 23.01.2026 03:28:39
  • Zuletzt bearbeitet 30.01.2026 19:36:59

Open WebUI Cleartext Transmission of Credentials Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Open WebUI. Authentication is not required to e...

  • EPSS 27.23%
  • Veröffentlicht 23.01.2026 03:28:35
  • Zuletzt bearbeitet 30.01.2026 19:47:56

Open WebUI load_tool_module_by_id Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Open WebUI. Authentication is required to exploit this vulnerab...

  • EPSS 1.69%
  • Veröffentlicht 23.01.2026 03:28:32
  • Zuletzt bearbeitet 30.01.2026 19:48:35

Open WebUI PIP install_frontmatter_requirements Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Open WebUI. Authentication is required to exploit...

  • EPSS 0.55%
  • Veröffentlicht 18.12.2025 00:00:00
  • Zuletzt bearbeitet 29.06.2026 20:17:20

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

Exploit
  • EPSS 0.23%
  • Veröffentlicht 04.12.2025 20:46:36
  • Zuletzt bearbeitet 10.12.2025 15:35:25

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.37, a Stored XSS vulnerability was discovered in Open-WebUI's Notes PDF download functionality. An attacker can import a Markdown file con...

Exploit
  • EPSS 4.5%
  • Veröffentlicht 04.12.2025 19:55:13
  • Zuletzt bearbeitet 10.12.2025 15:18:38

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.37, a Server-Side Request Forgery (SSRF) vulnerability in Open WebUI allows any authenticated user to force the server to make HTTP reques...