Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

open-webui — Vulnerabilities & Security Advisories 40

Browse all 40 CVE security advisories affecting open-webui. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Open-webui serves as a self-hosted, feature-rich interface for interacting with large language models, primarily enabling users to deploy and manage AI applications locally or within private networks. Its architecture, which bridges web clients with backend model services, has historically exposed it to critical vulnerabilities, including Remote Code Execution (RCE), Cross-Site Scripting (XSS), and improper access control issues. With forty recorded CVEs, the software frequently suffers from insecure direct object references and authentication bypasses, often stemming from complex integration layers between the UI and underlying model APIs. Recent incidents highlight risks related to unvalidated file uploads and session management flaws, allowing attackers to escalate privileges or execute arbitrary commands. These recurring security gaps underscore the necessity for rigorous input validation and strict permission controls when deploying open-webui in production environments, particularly given its role in handling sensitive data interactions.

Found 25 results / 40Clear Filters
Top products by open-webui: open-webui/open-webui open-webui
CVE IDTitleCVSSSeverityPublished
CVE-2024-8017 Cross-site Scripting (XSS) in open-webui/open-webui — open-webui/open-webuiCWE-79 5.4 -2025-03-20
CVE-2024-7053 Session Fixation in open-webui/open-webui — open-webui/open-webuiCWE-79 8.0 -2025-03-20
CVE-2024-8053 Improper Authentication in open-webui/open-webui — open-webui/open-webuiCWE-306 9.1 -2025-03-20
CVE-2024-7806 Remote Code Execution by Non-Admin Users via CSRF in open-webui/open-webui — open-webui/open-webuiCWE-352 8.8 -2025-03-20
CVE-2024-7039 Improper Privilege Management in open-webui/open-webui — open-webui/open-webuiCWE-863 6.5 -2025-03-20
CVE-2024-12534 Denial of Service (DoS) in open-webui/open-webui — open-webui/open-webuiCWE-400 7.5 -2025-03-20
CVE-2024-7034 Remote Code Execution due to Arbitrary File Write in open-webui/open-webui — open-webui/open-webuiCWE-22 9.1 -2025-03-20
CVE-2024-7043 Improper Access Control in open-webui/open-webui — open-webui/open-webuiCWE-862 9.8 -2025-03-20
CVE-2024-7983 Denial of Service in open-webui/open-webui — open-webui/open-webuiCWE-770 7.5 -2025-03-20
CVE-2024-7044 Stored XSS in open-webui/open-webui — open-webui/open-webuiCWE-79 6.1 -2025-03-20
CVE-2024-7045 Improper Access Control in open-webui/open-webui — open-webui/open-webuiCWE-862 5.3 -2025-03-20
CVE-2024-7035 Cross-Site Request Forgery (CSRF) in open-webui/open-webui — open-webui/open-webuiCWE-352 8.1 -2025-03-20
CVE-2024-7036 Denial of Service in open-webui/open-webui — open-webui/open-webuiCWE-400 7.5 -2025-03-20
CVE-2024-7033 Arbitrary File Write in open-webui/open-webui — open-webui/open-webuiCWE-29 9.8 -2025-03-20
CVE-2024-8060 Remote Code Execution in OpenWebUI via Arbitrary File Upload — open-webui/open-webuiCWE-22 8.8 -2025-03-20
CVE-2024-7040 Improper Access Control in open-webui/open-webui — open-webui/open-webuiCWE-639 2.7 -2025-03-20
CVE-2024-7046 Improper Access Control in open-webui/open-webui — open-webui/open-webuiCWE-862 5.3 -2025-03-20
CVE-2024-12537 Unauthenticated Denial of Service in open-webui/open-webui — open-webui/open-webuiCWE-770 7.5 -2025-03-20
CVE-2024-7959 SSRF in open-webui/open-webui — open-webui/open-webuiCWE-918 9.8 -2025-03-20
CVE-2024-7990 Stored Cross-Site Scripting in open-webui/open-webui — open-webui/open-webuiCWE-79 5.4 -2025-03-20
CVE-2024-7049 Exposure of Token in open-webui/open-webui — open-webui/open-webuiCWE-488 8.1AIHighAI2024-10-10
CVE-2024-7048 IDOR in open-webui/open-webui — open-webui/open-webuiCWE-863 8.8AIHighAI2024-10-10
CVE-2024-7041 IDOR in open-webui/open-webui — open-webui/open-webuiCWE-639 4.3AIMediumAI2024-10-09
CVE-2024-7037 Arbitrary File Write/Delete Leading to RCE in open-webui/open-webui — open-webui/open-webuiCWE-22 9.8AICriticalAI2024-10-09
CVE-2024-7038 Information Disclosure in open-webui/open-webui — open-webui/open-webuiCWE-209 6.5AIMediumAI2024-10-09

This page lists every published CVE security advisory associated with open-webui. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.