Open Webui
Vendor:
First CVE: Apr 16, 2024 · Active for 2 years
134
Total CVEs
More Total CVEs than 99% of tracked products
44.7
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 33% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Open Webui over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 16, 2024
2 years ago
Most Recent CVE
Jul 15, 2026
9 days ago
CVE Severity & Scoring
Open Webui134 CVEs
51%
41%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network133 (99.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (0.7%)
Attack Complexity
Low126 (94.0%)
High8 (6.0%)
Unknown0 (0.0%)
User Interaction
None100 (74.6%)
Unknown0 (0.0%)
Required34 (25.4%)
Privileges Required
Low108 (80.6%)
High8 (6.0%)
None18 (13.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (134 CVEs).
134 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-44551CRITICAL Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the LDAP authentication endpoint does not validate that the submi | May 15, 2026 | 9.1 | 47 | NO | YES |
CVE-2026-56400CRITICAL open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functio | Jul 15, 2026 | 9.6 | 39 | NO | NO |
CVE-2026-0766HIGH Open WebUI load_tool_module_by_id Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installati | Jan 23, 2026 | 8.8 | 39 | NO | NO |
CVE-2026-56398CRITICAL Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL MIME type is inferred from file extension | Jul 15, 2026 | 9.0 | 37 | NO | NO |
CVE-2026-59216CRITICAL Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and execute:tool Socket.IO events to | Jul 9, 2026 | 9.0 | 37 | NO | NO |
CVE-2026-59214CRITICAL Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, Open WebUI runs client-side Python with Pyodide in a same-origin web worker, | Jul 9, 2026 | 9.0 | 37 | NO | NO |
CVE-2026-54008HIGH Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, backend/open_webui/utils/oauth.py::_process_picture_url calls val | Jun 23, 2026 | 8.5 | 37 | NO | NO |
CVE-2026-54010HIGH Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI lets an authenticated user attach arbitrary file_id va | Jun 23, 2026 | 8.3 | 35 | NO | NO |
CVE-2026-44566CRITICAL Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.1.124, when attaching files to a promp, the name of the file is derive | May 15, 2026 | 9.8 | 35 | NO | NO |
CVE-2025-64496HIGH Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Versions 0.6.224 and prior contain a code injection vulnerability in the Direct C | Nov 8, 2025 | 8.0 | 34 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (134 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
1.5% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (134 CVEs).
Media Mentions
Signals from CVEs in this product scope (134 CVEs).
Top CNAs Publishing CVEs For Open Webui
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 0.9.6 | 2 | 6.5 | 0.3% | 0 | 0 |
| 0.6.41 | 1 | 4.3 | 0.3% | 0 | 0 |
| 0.6.32 | 3 | 8.0 | 9.7% | 0 | 0 |
| 0.3.8 | 13 | 6.9 | 0.6% | 0 | 0 |
| 0.3.32 | 2 | 7.5 | 0.9% | 0 | 0 |
| 0.3.10 | 1 | 8.2 | 0.6% | 0 | 0 |
| 0.1.105 | 2 | 7.5 | 0.8% | 0 | 0 |