İçeriğe atla
Noroxi

openwebui kayıtları

openwebui üreticisine ait 155 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
2
Düzeltme kaydı olan
%97,4
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

155 kayıt
  • CVE-2026-44566
    39İzleyin

    Open WebUI: Arbitrary File Upload and Path Traversal

    KritikCVSS 9,8İstismar yokEPSS %0

    openwebui · open webui15 May 2026

  • CVE-2026-44551
    36İzleyin

    Open WebUI: LDAP Empty Password Authentication Bypass

    KritikCVSS 9,1Kavram kanıtıEPSS %2

    openwebui · open webui15 May 2026

  • CVE-2024-8017
    36İzleyin

    Cross-site Scripting (XSS) in open-webui/open-webui

    KritikCVSS 9,0İstismar yokEPSS %1

    openwebui · open webui20 Mar 2025

  • CVE-2026-56400
    36İzleyin

    open-webui - Remote Code Execution via CORS Misconfiguration and Session Validation

    KritikCVSS 9,0İstismar yokEPSS %1

    openwebui · open webui15 Tem 2026

  • CVE-2026-59216
    36İzleyin

    Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id

    KritikCVSS 9,0İstismar yokEPSS %0

    openwebui · open webui9 Tem 2026

  • CVE-2026-59214
    36İzleyin

    Open WebUI: Stored web worker XSS via Pyodide

    KritikCVSS 9,0İstismar yokEPSS %0

    openwebui · open webui9 Tem 2026

  • CVE-2024-6707
    35İzleyin

    Open WebUI Arbitrary File Upload + Path Traversal

    YüksekCVSS 8,8İstismar yokEPSS %1

    openwebui · open webui7 Ağu 2024

  • CVE-2024-7043
    35İzleyin

    Improper Access Control in open-webui/open-webui

    YüksekCVSS 8,8İstismar yokEPSS %1

    openwebui · open webui20 Mar 2025

  • CVE-2026-45672
    35İzleyin

    Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassed

    YüksekCVSS 8,8İstismar yokEPSS %1

    openwebui · open webui15 May 2026

  • CVE-2026-70482
    35İzleyin

    Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client

    YüksekCVSS 8,8İstismar yokEPSS %1

    openwebui · open webui4 Ağu 2026

  • CVE-2024-7044
    35İzleyin

    Stored XSS in open-webui/open-webui

    YüksekCVSS 8,9İstismar yokEPSS %1

    openwebui · open webui20 Mar 2025

  • CVE-2025-64496
    34İzleyin

    Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events

    YüksekCVSS 8,0İstismar yokEPSS %8

    openwebui · open webui7 Kas 2025

  • CVE-2026-56398
    34İzleyin

    Open WebUI - Stored Cross-Site Scripting via OAuth Picture Claim SVG Data URI

    YüksekCVSS 8,5İstismar yokEPSS %1

    openwebui · open webui15 Tem 2026

  • CVE-2026-44552
    34İzleyin

    Open WebUI: Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Poisoning

    YüksekCVSS 8,7İstismar yokEPSS %0

    openwebui · open webui15 May 2026

  • CVE-2026-87995
    34İzleyin

    Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin

    YüksekCVSS 8,7İstismar yokEPSS %0

    openwebui · open webui9 Eyl 2026

  • CVE-2026-44549
    34İzleyin

    Open WebUI: Stored XSS in excel file preview

    YüksekCVSS 8,7İstismar yokEPSS %0

    openwebui · open webui15 May 2026

  • CVE-2026-45331
    34İzleyin

    Open WebUI: Full SSRF Vulnerability in the RAG Web Search Feature

    YüksekCVSS 8,5İstismar yokEPSS %0

    openwebui · open webui15 May 2026

  • CVE-2026-45400
    34İzleyin

    Open WebUI: Server-Side Request Forgery (SSRF) bypass in `validate_url`

    YüksekCVSS 8,5İstismar yokEPSS %0

    openwebui · open webui15 May 2026

  • CVE-2026-45401
    34İzleyin

    Open WebUI: SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints

    YüksekCVSS 8,5Kavram kanıtıEPSS %0

    openwebui · open webui15 May 2026

  • CVE-2026-54008
    34İzleyin

    Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url`

    YüksekCVSS 8,5İstismar yokEPSS %0

    openwebui · open webui23 Haz 2026

  • CVE-2026-45315
    34İzleyin

    Open WebUI: Stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptions

    YüksekCVSS 8,7İstismar yokEPSS %0

    openwebui · open webui15 May 2026

  • CVE-2026-44570
    33İzleyin

    Open WebUI: Inconsistent authorization controls within memories API

    YüksekCVSS 8,3İstismar yokEPSS %0

    openwebui · open webui15 May 2026

  • CVE-2026-54010
    33İzleyin

    Open WebUI: Forged chat-file link allows cross-user file read and deletion

    YüksekCVSS 8,3İstismar yokEPSS %0

    openwebui · open webui23 Haz 2026

  • CVE-2024-8053
    32İzleyin

    Improper Authentication in open-webui/open-webui

    YüksekCVSS 8,2İstismar yokEPSS %1

    openwebui · open webui20 Mar 2025

  • CVE-2026-87016
    32İzleyin

    Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite

    YüksekCVSS 8,1İstismar yokEPSS %1

    openwebui · open webui9 Eyl 2026