Openwebui

Open Webui

175 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.4%
  • Veröffentlicht 20.03.2025 10:10:18
  • Zuletzt bearbeitet 13.08.2026 15:18:32

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Exploit
  • EPSS 0.24%
  • Veröffentlicht 20.03.2025 10:10:03
  • Zuletzt bearbeitet 29.07.2025 18:06:09

In version v0.3.8 of open-webui/open-webui, sensitive actions such as deleting and resetting are performed using the GET method. This vulnerability allows an attacker to perform Cross-Site Request Forgery (CSRF) attacks, where an unaware user can uni...

Exploit
  • EPSS 0.8%
  • Veröffentlicht 20.03.2025 10:09:57
  • Zuletzt bearbeitet 13.08.2026 15:18:08

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Exploit
  • EPSS 1.13%
  • Veröffentlicht 20.03.2025 10:09:54
  • Zuletzt bearbeitet 16.07.2026 16:17:19

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Exploit
  • EPSS 0.89%
  • Veröffentlicht 20.03.2025 10:09:10
  • Zuletzt bearbeitet 13.08.2026 15:17:55

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • EPSS 0.09%
  • Veröffentlicht 20.03.2025 10:09:04
  • Zuletzt bearbeitet 15.04.2025 16:15:47

Rejected reason: ** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-53981. Notes: All CVE users should reference CVE-2024-53981 instead of this CVE Record. All references and descriptions in this candidate ...

Exploit
  • EPSS 24.46%
  • Veröffentlicht 20.03.2025 10:09:00
  • Zuletzt bearbeitet 16.07.2026 16:18:43

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Exploit
  • EPSS 0.9%
  • Veröffentlicht 20.03.2025 10:08:55
  • Zuletzt bearbeitet 13.08.2026 15:19:13

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Exploit
  • EPSS 0.35%
  • Veröffentlicht 10.10.2024 08:15:03
  • Zuletzt bearbeitet 11.09.2026 10:16:49

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Exploit
  • EPSS 0.37%
  • Veröffentlicht 10.10.2024 02:15:03
  • Zuletzt bearbeitet 15.10.2025 13:15:51

In version v0.3.8 of open-webui, an improper privilege management vulnerability exists in the API endpoints GET /api/v1/documents/ and POST /rag/api/v1/doc. This vulnerability allows a lower-privileged user to access and overwrite files managed by a ...