open-webui vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-64495Highopen-webui: Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCEGHSA-5CCF-884P-4JJQHighopen-webui: Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) VulnerabilityCVE-2024-8060Highopen-webui: Open WebUI allows Remote Code Execution via Arbitrary File Upload to /audio/api/v1/transcriptionsCVE-2024-8053Highopen-webui: Open WebUI lacks authentication for the `api/v1/utils/pdf` endpointCVE-2024-7983Highopen-webui: Open WebUI denial of service through endpoint for converting markdownCVE-2024-7990Highopen-webui: Open WebUI stored cross-site scripting (XSS) vulnerabilityCVE-2024-7035Mediumopen-webui: Open WebUI Vulnerable to Cross-Site Request Forgery (CSRF)CVE-2024-7806Highopen-webui: Open WebUI Cross-Site Request Forgery (CSRF) VulnerabilityCVE-2024-7959Highopen-webui: Open WebUI has SSRF in /openai/modelsGHSA-6WJ5-5PGR-JWQ8Highopen-webui: Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability in api/chat/fileCVE-2024-7045Mediumopen-webui: Open WebUI Has Improper Access Control Leading to Arbitrary Prompt ReadCVE-2024-7053Highopen-webui: Open WebUI Vulnerable to a Session Fixation AttackCVE-2024-7046Mediumopen-webui: Open WebUI Allows Viewing of Admin DetailsCVE-2024-7044Mediumopen-webui: Open WebUI Vulnerable to Cross-Site Scripting (XSS) via Chat File UploadCVE-2024-7033Mediumopen-webui: Open WebUI Allows Arbitrary File Write via the `download_model` EndpointCVE-2024-7039Highopen-webui: Open WebUI Allows Admin Deletion via API EndpointCVE-2024-7036Highopen-webui: Open WebUI Uncontrolled Resource Consumption vulnerabilityCVE-2024-7043Highopen-webui: Open WebUI Allows Arbitrary File Reading and DeletionCVE-2024-7034Mediumopen-webui: Open WebUI Allows Arbitrary File Write via the `/models/upload` EndpointGHSA-W466-2WFC-8G58Highopen-webui: Open WebUI has vulnerable dependency on starlette via fastapiCVE-2024-12537Highopen-webui: Open WebUI Uncontrolled Resource Consumption vulnerabilityCVE-2024-12534Highopen-webui: Open WebUI Uncontrolled Resource Consumption vulnerabilityCVE-2024-7037Mediumopen-webui: open-webui allows writing and deleting arbitrary filesCVE-2024-7041Mediumopen-webui: open-webui Insecure Direct Object Reference (IDOR) vulnerabilityCVE-2024-7038Lowopen-webui: open-webui allows enumeration of file names and traversal of directories by observing the error messages

Stop the waste.
Protect your environment with Kodem.