VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5681 CVEsRSS

CVE-2026-45318Medium· 5.4
4mo ago

Open WebUI has stored XSS via unsanitized Office/Excel/DOCX file preview rendering ({@html} without DOMPurify)

Open WebUI has stored XSS via unsanitized Office/Excel/DOCX file preview rendering ({@html} without DOMPurify)

▾ Sunlitopen-webui · open-webuiEPSS 0.24%via OSV
CVE-2026-45675High· 8.1
4mo ago

Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts

Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts

▾ Twilightopen-webui · open-webuiEPSS 0.51%via OSV
CVE-2026-45387Medium· 4.3
4mo ago

Open WebUI: Sharing models for others to use (read permission) also exposes model details (system prompt leakage)

Open WebUI: Sharing models for others to use (read permission) also exposes model details (system prompt leakage)

▾ Sunlitopen-webui · open-webuiEPSS 0.31%via OSV
CVE-2026-45345Medium· 6.5
4mo ago

Open WebUI missing authorization check at the model update function - models from other users can be updated

Open WebUI missing authorization check at the model update function - models from other users can be updated

▾ Sunlitopen-webui · open-webuiEPSS 0.34%via OSV
CVE-2026-45349High· 7.1
4mo ago

Open WebUI has Broken Access Control for Completions API

Open WebUI has Broken Access Control for Completions API

▾ Twilightopen-webui · open-webuiEPSS 0.33%via OSV
CVE-2026-45348High· 8.7
4mo ago

pyLoad is vulnerable to stored XSS in Downloads view via unsanitized link URL in packages.js template literal

pyLoad is vulnerable to stored XSS in Downloads view via unsanitized link URL in packages.js template literal

▾ Twilightpyload-ng · pyload-ngEPSS 0.35%via OSV
CVE-2026-45347Medium· 4.3
4mo ago

Open WebUI vulnerable to blind server side request forgery (SSRF) via the PDF generate function

Open WebUI vulnerable to blind server side request forgery (SSRF) via the PDF generate function

▾ Sunlitopen-webui · open-webuiEPSS 0.25%via OSV
CVE-2026-44722Medium· 6.2
4mo ago

pyzipper has an encryption bypass for small files encrypted using it

pyzipper has an encryption bypass for small files encrypted using it

▾ Sunlitpyzipper · pyzipperEPSS 0.12%via OSV
CVE-2026-43977High· 7.5
4mo ago

wger Vulnerable to IDOR: Authenticated Users Can Read Any User's Private Workout Session Data via Template Routine API

wger Vulnerable to IDOR: Authenticated Users Can Read Any User's Private Workout Session Data via Template Routine API

▾ Twilightwger · wgerEPSS 0.39%via OSV
CVE-2026-44899Medium· 4.7
4mo ago

Mistune Image Directive CSS Injection Vulnerability

Mistune Image Directive CSS Injection Vulnerability

▾ Sunlitmistune · mistuneEPSS 0.27%via OSV
CVE-2026-43978High· 8.1
4mo ago

wger: Privilege escalation via trainer-login session chaining allows gym trainer to impersonate gym manager

wger: Privilege escalation via trainer-login session chaining allows gym trainer to impersonate gym manager

▾ Twilightwger · wgerEPSS 0.37%via OSV
CVE-2026-45400High· 8.5
4mo ago

Open WebUI has a Server-Side Request Forgery (SSRF) bypass in `validate_url`

Open WebUI has a Server-Side Request Forgery (SSRF) bypass in `validate_url`

▾ Twilightopen-webui · open-webuiEPSS 0.33%via OSV
CVE-2026-45399High· 7.1
4mo ago

Open WebUI: Low-privilege authenticated users can enumerate and stop global background tasks, causing system-wide chat disruption

Open WebUI: Low-privilege authenticated users can enumerate and stop global background tasks, causing system-wide chat disruption

▾ Twilightopen-webui · open-webuiEPSS 0.39%via OSV
CVE-2026-44969Low· 2.5
4mo ago

dbt MCP Server Logs Tool Arguments Including SQL Queries and Credentials in Plaintext Without Redaction When File Logging Is Enabled

dbt MCP Server Logs Tool Arguments Including SQL Queries and Credentials in Plaintext Without Redaction When File Logging Is Enabled

▾ Sunlitdbt-mcp · dbt-mcpEPSS 0.17%via OSV
CVE-2026-45299Medium· 5.4
4mo ago

Open WebUI has Stored Cross-Site Scripting In Profile Picture

Open WebUI has Stored Cross-Site Scripting In Profile Picture

▾ Sunlitopen-webui · open-webuiEPSS 0.23%via OSV
CVE-2026-45397Medium· 5.3PoC
4mo ago

Open WebUI Vulnerable to Unauthenticated RAG Configuration Disclosure

Open WebUI Vulnerable to Unauthenticated RAG Configuration Disclosure

▾ Twilightopen-webui · open-webuiEPSS 0.81%via OSV
CVE-2026-44898Medium· 6.1
4mo ago

Mistune TOC Anchor Injection XSS

Mistune TOC Anchor Injection XSS

▾ Sunlitmistune · mistuneEPSS 0.27%via OSV
CVE-2026-45370High· 7.7
4mo ago

python-utcp: Full Process Environment Exposed to CLI Subprocess - Secrets Leakage via Command Injection

python-utcp: Full Process Environment Exposed to CLI Subprocess - Secrets Leakage via Command Injection

▾ Twilightutcp-cli · utcp-cliEPSS 0.37%via OSV
CVE-2026-44541High
4mo ago

ethyca-fides has a DOM-based XSS vulnerability in fides.js via fides_description override

ethyca-fides has a DOM-based XSS vulnerability in fides.js via fides_description override

▾ Twilightethyca-fides · ethyca-fidesEPSS 0.52%via OSV
CVE-2026-45386Medium· 4.3
4mo ago

Open WebUI has an IDOR vulnerability in the pin_channel_message API endpoint

Open WebUI has an IDOR vulnerability in the pin_channel_message API endpoint

▾ Sunlitopen-webui · open-webuiEPSS 0.29%via OSV
CVE-2026-45303High· 7.7
4mo ago

Open WebUI has stored XSS via the HTML renedering view

Open WebUI has stored XSS via the HTML renedering view

▾ Twilightopen-webui · open-webuiEPSS 0.30%via OSV
CVE-2026-45331High· 8.5
4mo ago

Open WebUI has a full SSRF Vulnerability in the RAG Web Search Feature

Open WebUI has a full SSRF Vulnerability in the RAG Web Search Feature

▾ Twilightopen-webui · open-webuiEPSS 0.33%via OSV
CVE-2026-45350High· 7.1
4mo ago

Open WebUI's chat completion API allows tool restrictions to be bypassed

Open WebUI's chat completion API allows tool restrictions to be bypassed

▾ Twilightopen-webui · open-webuiEPSS 0.37%via OSV
CVE-2026-44919Medium· 4.3
4mo ago

OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices

OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices

▾ Sunlitironic · ironicEPSS 0.56%via OSV
CVE-2026-45398High· 7.5
4mo ago

Open WebUI Vulnerable to IDOR: Retrieval API Bypasses Knowledge Base Access Controls

Open WebUI Vulnerable to IDOR: Retrieval API Bypasses Knowledge Base Access Controls

▾ Twilightopen-webui · open-webuiEPSS 0.49%via OSV
CVE-2026-45672High· 8.8
4mo ago

Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassed

Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassed

▾ Twilightopen-webui · open-webuiEPSS 0.59%via OSV
CVE-2026-45314Medium· 6.1
4mo ago

Open WebUI has XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image

Open WebUI has XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image

▾ Sunlitopen-webui · open-webuiEPSS 0.24%via OSV
CVE-2026-45671High· 8.0
4mo ago

Open WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletion

Open WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletion

▾ Twilightopen-webui · open-webuiEPSS 0.39%via OSV
CVE-2026-45338High· 7.7
4mo ago

Open WebUI Vulnerable to SSRF via OAuth Profile Picture URL in _process_picture_url (oauth.py)

Open WebUI Vulnerable to SSRF via OAuth Profile Picture URL in _process_picture_url (oauth.py)

▾ Twilightopen-webui · open-webuiEPSS 0.38%via OSV
CVE-2026-44885Medium· 5.5
4mo ago

Portainer has a path traversal in backup archive extraction that allows arbitrary file write

Portainer has a path traversal in backup archive extraction that allows arbitrary file write

▾ Sunlitportainer · github.com/portainer/portainerEPSS 0.80%via OSV
CVEs tagged “osv” — page 63 · VulnSea