Open Webui

Vendor:

First CVE: Apr 16, 2024 · Active for 2 years

134
Total CVEs
More Total CVEs than 99% of tracked products
44.7
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 33% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Open Webui over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 16, 2024
2 years ago
Most Recent CVE
Jul 15, 2026
9 days ago

CVE Severity & Scoring

Open Webui134 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network133 (99.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (0.7%)
Attack Complexity
Low126 (94.0%)
High8 (6.0%)
Unknown0 (0.0%)
User Interaction
None100 (74.6%)
Unknown0 (0.0%)
Required34 (25.4%)
Privileges Required
Low108 (80.6%)
High8 (6.0%)
None18 (13.4%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (134 CVEs).

134 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the LDAP authentication endpoint does not validate that the submi
May 15, 20269.147NOYES
open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functio
Jul 15, 20269.639NONO
Open WebUI load_tool_module_by_id Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installati
Jan 23, 20268.839NONO
Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL MIME type is inferred from file extension
Jul 15, 20269.037NONO
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and execute:tool Socket.IO events to
Jul 9, 20269.037NONO
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, Open WebUI runs client-side Python with Pyodide in a same-origin web worker,
Jul 9, 20269.037NONO
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, backend/open_webui/utils/oauth.py::_process_picture_url calls val
Jun 23, 20268.537NONO
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI lets an authenticated user attach arbitrary file_id va
Jun 23, 20268.335NONO
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.1.124, when attaching files to a promp, the name of the file is derive
May 15, 20269.835NONO
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Versions 0.6.224 and prior contain a code injection vulnerability in the Direct C
Nov 8, 20258.034NONO

Exploit Exposure

Signals from CVEs in this product scope (134 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
1.5% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (134 CVEs).

Media Mentions

Signals from CVEs in this product scope (134 CVEs).

Top CNAs Publishing CVEs For Open Webui

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
0.9.626.50.3%00
0.6.4114.30.3%00
0.6.3238.09.7%00
0.3.8136.90.6%00
0.3.3227.50.9%00
0.3.1018.20.6%00
0.1.10527.50.8%00