Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| open-webui | open-webui | < 0.9.6 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54011 | 8.7 HIGH | Open WebUI: Stored XSS in Mermaid Markdown Preview |
| CVE-2026-54008 | 8.5 HIGH | Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url` |
| CVE-2026-54010 | 8.3 HIGH | Open WebUI: Forged chat-file link allows cross-user file read and deletion |
| CVE-2026-54018 | 7.7 HIGH | Open WebUI: SSRF Protection Bypass in Playwright Web Loader via HTTP Redirects |
| CVE-2026-54013 | 7.6 HIGH | Open WebUI: Stored XSS to Account Takeover via Model Profile Images in Open WebUI |
| CVE-2026-54012 | 7.1 HIGH | Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion |
| CVE-2026-54009 | 6.5 MEDIUM | Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field |
| CVE-2026-54019 | 6.5 MEDIUM | Open WebUI: RAG ACL Bypass in Milvus Multitenancy Mode |
| CVE-2026-54015 | 6.4 MEDIUM | Open WebUI: Prompt history IDOR: unbound history_id allows cross-prompt read and deletion |
| CVE-2026-54021 | 6.3 MEDIUM | Open WebUI: Authenticated users can target arbitrary configured Ollama backends via unguar |
| CVE-2026-54022 | 5.3 MEDIUM | Open WebUI: Any authenticated user can read other users' private notes via Socket.IO |
| CVE-2026-54006 | 4.3 MEDIUM | Open WebUI: Calendar event re-parenting allows writing events into another user's calendar |
| CVE-2026-54014 | 4.3 MEDIUM | Open WebUI: Sibling-Prefix Path Traversal via /cache/{path} in open-webui/open-webui |
| CVE-2026-54007 | Open WebUI: Cross-origin postMessage confirmation bypass via action:submit |
No comments yet