Openwebui

Open Webui

175 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.37%
  • Veröffentlicht 09.10.2024 20:15:09
  • Zuletzt bearbeitet 15.10.2025 13:15:51

An Insecure Direct Object Reference (IDOR) vulnerability exists in open-webui/open-webui version v0.3.8. The vulnerability occurs in the API endpoint `http://0.0.0.0:3000/api/v1/memories/{id}/update`, where the decentralization design is flawed, allo...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 09.10.2024 19:15:14
  • Zuletzt bearbeitet 16.07.2026 16:18:07

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Exploit
  • EPSS 0.66%
  • Veröffentlicht 07.08.2024 23:15:41
  • Zuletzt bearbeitet 21.11.2024 09:50:09

Attackers can craft a malicious prompt that coerces the language model into executing arbitrary JavaScript in the context of the web page.

Exploit
  • EPSS 1%
  • Veröffentlicht 07.08.2024 23:15:41
  • Zuletzt bearbeitet 21.11.2024 09:50:09

Attacker controlled files can be uploaded to arbitrary locations on the web server's filesystem by abusing a path traversal vulnerability.

Exploit
  • EPSS 0.41%
  • Veröffentlicht 16.04.2024 15:15:36
  • Zuletzt bearbeitet 30.06.2025 14:30:00

Open WebUI is a user-friendly WebUI for LLMs. Open-webui is vulnerable to authenticated blind server-side request forgery. This vulnerability is fixed in 0.1.117.