CVE-2026-44566 - Open WebUI: Arbitrary File Upload and Path Traversal
Autor Mai 16, 2026 0 0
CVE-2026-44570 - Open WebUI: Inconsistent authorization controls within memories API
Autor Mai 16, 2026 0 0
CVE-2026-44567 - Open WebUI: Open WebUI Improper Authorization Control
Autor Mai 16, 2026 0 0
CVE-2026-44569 - Open WebUI: Insecure Message Access Breaks Authorization
Autor Mai 16, 2026 0 0
CVE-2026-45318 - Open WebUI: Stored XSS via unsanitized Office/Excel/DOCX file preview rendering ({@html} without DOMPur...
Autor Mai 16, 2026 0 0
CVE-2026-45338 - Open WebUI: SSRF via OAuth Profile Picture URL in _process_picture_url (oauth.py)
Autor Mai 16, 2026 0 0
CVE-2026-45317 - Open WebUI: Cross-Site Request Forgery (CSRF) via Image URL Manipulation
Autor Mai 16, 2026 0 0
CVE-2026-45665 - Open WebUI: Stored XSS in Banner Component via Improper Sanitization Order
Autor Mai 16, 2026 0 0
CVE-2026-45365 - Open WebUI: Authenticated users can bypass model access control via exposed query parameter
Autor Mai 16, 2026 0 0
CVE-2026-45351 - Open WebUI: Exposure of System Prompt to Regular User [Non-Admin]
Autor Mai 16, 2026 0 0
CVE-2026-45347 - Open WebUI: Blind server side request forgery (SSRF) via the PDF generate function
Autor Mai 16, 2026 0 0
CVE-2026-45667 - Open WebUI: Unauthenticated endpoint can trigger embedding generation (cost/DoS)
Autor Mai 16, 2026 0 0
CVE-2026-45666 - Open WebUI: Indirect Object Reference (IDOR) in user notes
Autor Mai 16, 2026 0 0
CVE-2026-8700 - Crypt::DSA versions before 1.20 for Perl generate seeds using rand
Autor Mai 16, 2026 0 0
CVE-2026-8704 - Crypt::DSA versions through 1.19 for Perl use 2-args open, allowing existing files to be modified
Autor Mai 16, 2026 0 0

