open-webui has 124 CVEs on record between 2024 and 2026. Disclosures have slowed: 21 in the last 90 days after 73 in the 90 before. The busiest recent month was May 2026 with 56. The median CVSS is 7.1 (high). None have a confirmed exploitation report. The dominant weakness classes are CWE-862 (9) and CWE-79 (7).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.1
- Publish → KEV
- —
- Last 90 days
- 21 prev 73
124
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2025-64495High· 8.7Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE60CVE-2026-45401High· 8.5Open WebUI has a SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints (not addressed by CVE-2025-65958)59CVE-2024-12537High· 7.5Open WebUI Uncontrolled Resource Consumption vulnerability53CVE-2026-45672High· 8.8Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassed49CVE-2026-54011High· 8.7Open WebUI: Stored XSS in Mermaid Markdown Preview48
open-webui vulnerabilities
CVEs affecting open-webui, newest first. Open any entry for full detail, references, and exploit status.
124 CVEsRSS
CVE-2024-7041Medium· 6.5open-webui Insecure Direct Object Reference (IDOR) vulnerability
open-webui Insecure Direct Object Reference (IDOR) vulnerability
▾ Sunlitopen-webui · open-webuiEPSS 0.37%via OSV
CVE-2024-7038Low· 2.7open-webui allows enumeration of file names and traversal of directories by observing the error messages
open-webui allows enumeration of file names and traversal of directories by observing the error messages
▾ Sunlitopen-webui · open-webuiEPSS 0.34%via OSV
CVE-2024-7037Medium· 6.5open-webui allows writing and deleting arbitrary files
open-webui allows writing and deleting arbitrary files
▾ Sunlitopen-webui · open-webuivia OSV
CVE-2024-6706Medium· 6.1Open WebUI Stored Cross-Site Scripting Vulnerability
Open WebUI Stored Cross-Site Scripting Vulnerability
▾ Sunlitopen-webui · open-webuiEPSS 0.66%via OSV