CVE-2024-7039
- EPSS 0.65%
- Veröffentlicht 20.03.2025 10:11:02
- Zuletzt bearbeitet 16.07.2026 16:18:19
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-12534
- EPSS 0.81%
- Veröffentlicht 20.03.2025 10:10:52
- Zuletzt bearbeitet 13.08.2026 15:17:25
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-7034
- EPSS 2.46%
- Veröffentlicht 20.03.2025 10:10:48
- Zuletzt bearbeitet 16.07.2026 16:17:53
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-7043
- EPSS 0.59%
- Veröffentlicht 20.03.2025 10:10:40
- Zuletzt bearbeitet 15.10.2025 13:15:51
An improper access control vulnerability in open-webui/open-webui v0.3.8 allows attackers to view and delete any files. The application does not verify whether the attacker is an administrator, allowing the attacker to directly call the GET /api/v1/f...
CVE-2024-7983
- EPSS 0.85%
- Veröffentlicht 20.03.2025 10:10:35
- Zuletzt bearbeitet 15.10.2025 13:15:53
In version 0.3.8 of open-webui, an endpoint for converting markdown to HTML is exposed without authentication. A maliciously crafted markdown payload can cause the server to spend excessive time converting it, leading to a denial of service. The serv...
CVE-2024-7044
- EPSS 0.51%
- Veröffentlicht 20.03.2025 10:10:23
- Zuletzt bearbeitet 29.07.2025 18:05:55
A Stored Cross-Site Scripting (XSS) vulnerability exists in the chat file upload functionality of open-webui/open-webui version 0.3.8. An attacker can inject malicious content into a file, which, when accessed by a victim through a URL or shared chat...
CVE-2024-12868
- EPSS 0.05%
- Veröffentlicht 20.03.2025 10:10:22
- Zuletzt bearbeitet 15.04.2025 16:15:21
Rejected reason: ** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-47874. Notes: All CVE users should reference CVE-2024-47874 instead of this CVE Record. All references and descriptions in this candidate ...
CVE-2024-7045
- EPSS 0.4%
- Veröffentlicht 20.03.2025 10:10:18
- Zuletzt bearbeitet 13.08.2026 15:18:32
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-7035
- EPSS 0.24%
- Veröffentlicht 20.03.2025 10:10:03
- Zuletzt bearbeitet 29.07.2025 18:06:09
In version v0.3.8 of open-webui/open-webui, sensitive actions such as deleting and resetting are performed using the GET method. This vulnerability allows an attacker to perform Cross-Site Request Forgery (CSRF) attacks, where an unaware user can uni...
CVE-2024-7036
- EPSS 0.8%
- Veröffentlicht 20.03.2025 10:09:57
- Zuletzt bearbeitet 13.08.2026 15:18:08
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.