VulnSea

open-webui has 124 CVEs on record between 2024 and 2026. Disclosures have slowed: 21 in the last 90 days after 73 in the 90 before. The busiest recent month was May 2026 with 56. The median CVSS is 7.1 (high). None have a confirmed exploitation report. The dominant weakness classes are CWE-862 (9) and CWE-79 (7).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.1
Publish → KEV
—
Last 90 days
21 prev 73

Products

  • open-webui 124
124
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

open-webui vulnerabilities

CVEs affecting open-webui, newest first. Open any entry for full detail, references, and exploit status.

124 CVEsRSS

CVE-2026-45386Medium· 4.3
4mo ago

Open WebUI has an IDOR vulnerability in the pin_channel_message API endpoint

Open WebUI has an IDOR vulnerability in the pin_channel_message API endpoint

▾ Sunlitopen-webui · open-webuiEPSS 0.29%via OSV
CVE-2026-45303High· 7.7
4mo ago

Open WebUI has stored XSS via the HTML renedering view

Open WebUI has stored XSS via the HTML renedering view

▾ Twilightopen-webui · open-webuiEPSS 0.30%via OSV
CVE-2026-45331High· 8.5
4mo ago

Open WebUI has a full SSRF Vulnerability in the RAG Web Search Feature

Open WebUI has a full SSRF Vulnerability in the RAG Web Search Feature

▾ Twilightopen-webui · open-webuiEPSS 0.33%via OSV
CVE-2026-45350High· 7.1
4mo ago

Open WebUI's chat completion API allows tool restrictions to be bypassed

Open WebUI's chat completion API allows tool restrictions to be bypassed

▾ Twilightopen-webui · open-webuiEPSS 0.37%via OSV
CVE-2026-45398High· 7.5
4mo ago

Open WebUI Vulnerable to IDOR: Retrieval API Bypasses Knowledge Base Access Controls

Open WebUI Vulnerable to IDOR: Retrieval API Bypasses Knowledge Base Access Controls

▾ Twilightopen-webui · open-webuiEPSS 0.49%via OSV
CVE-2026-45672High· 8.8
4mo ago

Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassed

Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassed

▾ Twilightopen-webui · open-webuiEPSS 0.59%via OSV
CVE-2026-45314Medium· 6.1
4mo ago

Open WebUI has XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image

Open WebUI has XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image

▾ Sunlitopen-webui · open-webuiEPSS 0.24%via OSV
CVE-2026-45671High· 8.0
4mo ago

Open WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletion

Open WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletion

▾ Twilightopen-webui · open-webuiEPSS 0.39%via OSV
CVE-2026-45338High· 7.7
4mo ago

Open WebUI Vulnerable to SSRF via OAuth Profile Picture URL in _process_picture_url (oauth.py)

Open WebUI Vulnerable to SSRF via OAuth Profile Picture URL in _process_picture_url (oauth.py)

▾ Twilightopen-webui · open-webuiEPSS 0.38%via OSV
CVE-2026-56400High· 8.3
4mo ago

Open WebUI has a CORS misconfiguration and session validation issue

Open WebUI has a CORS misconfiguration and session validation issue

▾ Twilightopen-webui · open-webuiEPSS 0.52%via OSV
CVE-2026-44569High· 7.1
4mo ago

Open WebUI's Insecure Message Access Breaks Authorization

Open WebUI's Insecure Message Access Breaks Authorization

▾ Twilightopen-webui · open-webuiEPSS 0.39%via OSV
CVE-2026-44571Medium· 6.5
4mo ago

Open WebUI's Improper Authorization in Standard Channels Allows Message Updates with Read Permission

Open WebUI's Improper Authorization in Standard Channels Allows Message Updates with Read Permission

▾ Sunlitopen-webui · open-webuiEPSS 0.34%via OSV
CVE-2026-44565High· 8.1
4mo ago

Open WebUI Arbitrary File Write, Delete via Path Traversal

Open WebUI Arbitrary File Write, Delete via Path Traversal

▾ Twilightopen-webui · open-webuiEPSS 0.54%via OSV
CVE-2026-44570High· 8.3
4mo ago

Open WebUI has inconsistent authorization controls within memories API

Open WebUI has inconsistent authorization controls within memories API

▾ Twilightopen-webui · open-webuiEPSS 0.42%via OSV
CVE-2026-44564Medium· 5.4
4mo ago

Read-Only Open WebUI Users Can Modify Collaborative Documents via Socket.IO

Read-Only Open WebUI Users Can Modify Collaborative Documents via Socket.IO

▾ Sunlitopen-webui · open-webuiEPSS 0.32%via OSV
CVE-2026-44563Medium· 5.4
4mo ago

Open WebUI's Ollama Model Access Control Bypass via /api/generate, /api/embed, /api/embeddings, and /api/show

Open WebUI's Ollama Model Access Control Bypass via /api/generate, /api/embed, /api/embeddings, and /api/show

▾ Sunlitopen-webui · open-webuiEPSS 0.34%via OSV
CVE-2026-44562Medium· 6.5
4mo ago

Open WebUI's Model Import Overwrites Any Model Without Ownership Check

Open WebUI's Model Import Overwrites Any Model Without Ownership Check

▾ Sunlitopen-webui · open-webuiEPSS 0.35%via OSV
CVE-2026-44549High· 7.3
4mo ago

Open WebUI has stored XSS in Excel file preview

Open WebUI has stored XSS in Excel file preview

▾ Twilightopen-webui · open-webuiEPSS 0.37%via OSV
CVE-2026-44550Medium· 5.0
4mo ago

Open WebUI's Mass Assignment via Pydantic extra='allow' Allows Creating Folders in Other Users' Accounts

Open WebUI's Mass Assignment via Pydantic extra='allow' Allows Creating Folders in Other Users' Accounts

▾ Sunlitopen-webui · open-webuiEPSS 0.29%via OSV
CVE-2026-44556High· 7.1
4mo ago

Open WebUI's responses passthrough endpoint lacks access control authorization

Open WebUI's responses passthrough endpoint lacks access control authorization

▾ Twilightopen-webui · open-webuiEPSS 0.37%via OSV
CVE-2026-44561Medium· 5.4
4mo ago

Open WebUI: Deactivated Channel Members Retain Full Access to Group/DM Channels

Open WebUI: Deactivated Channel Members Retain Full Access to Group/DM Channels

▾ Sunlitopen-webui · open-webuiEPSS 0.26%via OSV
CVE-2026-44560Medium· 6.5
4mo ago

Open WebUI has Unauthorized File and Knowledge Base Content Access via RAG Vector Search

Open WebUI has Unauthorized File and Knowledge Base Content Access via RAG Vector Search

▾ Sunlitopen-webui · open-webuiEPSS 0.38%via OSV
CVE-2026-44721High· 7.3
4mo ago

open-webui Vulnerable to Stored XSS via Model Description

open-webui Vulnerable to Stored XSS via Model Description

▾ Twilightopen-webui · open-webuiEPSS 0.37%via OSV
CVE-2026-44568Medium· 4.8
4mo ago

Open WebUI has Stored XSS in Pending User Overlay via Incorrect DOMPurify Application Order

Open WebUI has Stored XSS in Pending User Overlay via Incorrect DOMPurify Application Order

▾ Sunlitopen-webui · open-webuiEPSS 0.25%via OSV
CVE-2026-44559Medium· 4.3
4mo ago

Open WebUI Missing Access Check on Channel Members Endpoint for Standard Channels

Open WebUI Missing Access Check on Channel Members Endpoint for Standard Channels

▾ Sunlitopen-webui · open-webuiEPSS 0.30%via OSV
CVE-2026-44555High· 7.6
4mo ago

Open WebUI's Base Model Routing Bypasses Access Control via Model Chaining

Open WebUI's Base Model Routing Bypasses Access Control via Model Chaining

▾ Twilightopen-webui · open-webuiEPSS 0.35%via OSV
CVE-2026-44566High· 7.3
4mo ago

Open WebUI Vulnerable to Arbitrary File Upload and Path Traversal

Open WebUI Vulnerable to Arbitrary File Upload and Path Traversal

▾ Twilightopen-webui · open-webuiEPSS 0.46%via OSV
CVE-2026-44558Medium· 5.4
4mo ago

Open WebUI's Channel Access Grants Bypass filter_allowed_access_grants

Open WebUI's Channel Access Grants Bypass filter_allowed_access_grants

▾ Sunlitopen-webui · open-webuiEPSS 0.27%via OSV
CVE-2026-44554High· 8.1
4mo ago

Open WebUI has Knowledge Base Destruction and RAG Poisoning via Unauthorized Collection Overwrite

Open WebUI has Knowledge Base Destruction and RAG Poisoning via Unauthorized Collection Overwrite

▾ Twilightopen-webui · open-webuiEPSS 0.43%via OSV
CVE-2026-44557Medium· 4.3
4mo ago

Open WebUI vulnerable to Global Knowledge Base Enumeration via knowledge-bases Meta-Collection

Open WebUI vulnerable to Global Knowledge Base Enumeration via knowledge-bases Meta-Collection

▾ Sunlitopen-webui · open-webuiEPSS 0.30%via OSV
open-webui vulnerabilities (CVEs) — page 3 · VulnSea