Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-59214 |
|
Cross-Site Scripting (XSS) in open-webui (CVE-2026-59214)
cross-site scripting in open-webui (CVE-2026-59214). Confidential information can be exposed externally. Exploitable via ``pyodide.http.pyfetch``. Mitigation: upgrade to `0.10.0` or later.
|
| CVE-2026-59216 |
|
Code Injection in open-webui (CVE-2026-59216)
code injection in open-webui (CVE-2026-59216). Confidential information can be exposed externally. Exploitable via `POST /api/v1/chat/completions`. Mitigation: upgrade to `0.10.0` or later.
|
| CVE-2026-54011 |
|
Cross-Site Scripting (XSS) in open-webui (CVE-2026-54011)
cross-site scripting in open-webui (CVE-2026-54011). Confidential information can be exposed externally. Exploitable via ``innerHTML``. Mitigation: upgrade to `0.9.6` or later.
|
| CVE-2026-45672 |
|
Authorization Flaw in open-webui (CVE-2026-45672)
vulnerability in open-webui (CVE-2026-45672). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.8.12` or later.
|
| CVE-2026-45395 |
|
Privilege Escalation in open-webui (CVE-2026-45395)
vulnerability in open-webui (CVE-2026-45395). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/tools/id/{id}/update`. Mitigation: upgrade to `0.9.5` or later.
|
| CVE-2026-45345 |
|
Vulnerability in open-webui (CVE-2026-45345)
vulnerability in open-webui (CVE-2026-45345). Data can be tampered with by attackers. Exploitable via `POST /api/v1/models/model/update`. Mitigation: upgrade to `0.5.7` or later.
|
| CVE-2026-44568 |
|
Cross-Site Scripting (XSS) in open-webui (CVE-2026-44568)
cross-site scripting in open-webui (CVE-2026-44568). Risk of unauthorized operations or information disclosure. Exploitable via ``AccountPending.svelte``. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-44721 |
|
Cross-Site Scripting (XSS) in open-webui (CVE-2026-44721)
cross-site scripting in open-webui (CVE-2026-44721). Confidential information can be exposed externally. Exploitable via ``marked``. Mitigation: upgrade to `0.9.0` or later.
|