open-webui vulnerabilities
CVEs whose affected-version data names the open-webui package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
124 CVEsRSS
CVE-2024-7041Medium· 6.5open-webui Insecure Direct Object Reference (IDOR) vulnerability
open-webui Insecure Direct Object Reference (IDOR) vulnerability
▾ Sunlitopen-webui · open-webuiEPSS 0.37%via OSV
CVE-2024-7038Low· 2.7open-webui allows enumeration of file names and traversal of directories by observing the error messages
open-webui allows enumeration of file names and traversal of directories by observing the error messages
▾ Sunlitopen-webui · open-webuiEPSS 0.34%via OSV
CVE-2024-7037Medium· 6.5open-webui allows writing and deleting arbitrary files
open-webui allows writing and deleting arbitrary files
▾ Sunlitopen-webui · open-webuivia OSV
CVE-2024-6706Medium· 6.1Open WebUI Stored Cross-Site Scripting Vulnerability
Open WebUI Stored Cross-Site Scripting Vulnerability
▾ Sunlitopen-webui · open-webuiEPSS 0.66%via OSV