Openwebui
openwebui
141 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (141)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
A Stored Cross-Site Scripting (XSS) vulnerability exists in the chat file upload functionality of open-webui/open-webui version 0.3.8. An attacker can inject malicious content into a file, which, when accessed by a victi...Show more |
An improper access control vulnerability in open-webui/open-webui v0.3.8 allows attackers to view and delete any files. The application does not verify whether the attacker is an administrator, allowing the attacker to d...Show more |
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
In version v0.3.8 of open-webui/open-webui, sensitive actions such as deleting and resetting are performed using the GET method. This vulnerability allows an attacker to perform Cross-Site Request Forgery (CSRF) attacks,...Show more |
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
In version v0.3.8 of open-webui/open-webui, a vulnerability exists where a token is returned when a user with a pending role logs in. This allows the user to perform actions without admin confirmation, bypassing the inte...Show more |
In version v0.3.8 of open-webui, an improper privilege management vulnerability exists in the API endpoints GET /api/v1/documents/ and POST /rag/api/v1/doc. This vulnerability allows a lower-privileged user to access and...Show more |
An Insecure Direct Object Reference (IDOR) vulnerability exists in open-webui/open-webui version v0.3.8. The vulnerability occurs in the API endpoint `http://0.0.0.0:3000/api/v1/memories/{id}/update`, where the decentral...Show more |
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
Attacker controlled files can be uploaded to arbitrary locations on the web server's filesystem by abusing a path traversal vulnerability. |
Attackers can craft a malicious prompt that coerces the language model into executing arbitrary JavaScript in the context of the web page. |