openwebui has 37 CVEs on record. Disclosure cadence is accelerating: 37 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 18. The median CVSS is 6.5 (medium). None have a confirmed exploitation report. The dominant weakness classes are CWE-863 (9) and CWE-862 (8).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —
- Last 90 days
- 37 prev 0
Worst active — by depth score
CVE-2026-87995High· 8.7Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform60CVE-2026-87016High· 8.1Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform57CVE-2026-87011High· 7.5Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform53CVE-2026-87999High· 7.1Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform51CVE-2026-87015Medium· 6.8Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform49
openwebui vulnerabilities
CVEs affecting openwebui, newest first. Open any entry for full detail, references, and exploit status.
37 CVEsRSS
CVE-2026-70486High· 8.2Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch always granted allow-same-origin together with allow-scripts for HTML files s…
CVE-2026-70488Medium· 4.3Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync cleanup endpoint authorized write access to the knowledge base in the URL but then acted on directory and file ids su…
CVE-2026-70487Medium· 5.3Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, inline direct model metadata accepted client-supplied knowledge attachments without filtering them against the caller's read a…
CVE-2026-54020Medium· 6.3Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.0, Open WebUI resolved a hostname during URL validation and rejected private, loopback, and link-local addresses, but the HTTP clients re…
CVE-2026-70479High· 7.7Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, with WEB_LOADER_ENGINE=playwright, the Playwright web loader validates only the top-level page request and lets sub-resource r…
CVE-2026-59215Low· 3.1Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, channel thread parent and reply handling did not bind parent_id to the channel in the URL, allowing an authenticated user to reference…
CVE-2026-59216High· 7.7Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and execute:tool Socket.IO events to a client-supplied session_id after checking only that the…