Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2759▲ 5 respecto a la semana anterior
Críticas / altas1275▼ 253 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)242▲ 224 respecto a la semana anterior
9658 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.44% | — | Openwebui Open Webui | 15/5/2026 | 17/6/2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, Open WebUI allows admins to restrict which API endpoints an API key can access. When an API key is restricted from /api/v1/messages, requests using the Authorization: Bearer sk-... header are correctly… | |
| Analizada | Alta (8.5) | 0.33% | — | Openwebui Open Webui | 15/5/2026 | 17/6/2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, validate_url() in backend/open_webui/retrieval/web/utils.py calls validators.ipv6(ip, private=True), but the validators library does NOT implement the private keyword for IPv6 — the call raises a… | |
| Analizada | Media (4.8) | 0.25% | — | Openwebui Open Webui | 15/5/2026 | 17/6/2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the AccountPending.svelte component renders the admin-configured "Pending User Overlay Content" using marked.parse() inside {@html} with an incorrect DOMPurify application order. An admin can inject… | |
| Analizada | Media (5.4) | 0.32% | — | Openwebui Open Webui | 15/5/2026 | 17/6/2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the ydoc:document:update Socket.IO event handler checks whether the sender is a member of the document's Socket.IO room (line 678) but does not verify that the sender has write permission. Users with… | |
| Analizada | Media (5.4) | 0.34% | — | Openwebui Open Webui | 15/5/2026 | 17/6/2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the /api/generate, /api/embed, /api/embeddings, and /api/show endpoints accept any model name from the user and forward the request to the Ollama backend without checking whether the user is authorized to… | |
| Analizada | Media (6.5) | 0.35% | — | Openwebui Open Webui | 15/5/2026 | 17/6/2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the POST /api/v1/models/import endpoint allows users with the workspace.models_import permission to overwrite any existing model in the database, regardless of ownership. When an imported model's ID… | |
| Analizada | Media (5.4) | 0.26% | — | Openwebui Open Webui | 15/5/2026 | 17/6/2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the is_user_channel_member function checks whether a ChannelMember row exists but does not check the is_active field. When a user is deactivated from a group or DM channel (removed by the channel owner,… | |
| Analizada | Media (6.5) | 0.38% | — | Openwebui Open Webui | 15/5/2026 | 17/6/2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the type: "file" (non-full-context), type: "text" with collection_name, and bare collection_name/collection_names paths in the get_sources_from_items function perform vector store queries without any… | |
| Analizada | Media (4.3) | 0.30% | — | Openwebui Open Webui | 15/5/2026 | 17/6/2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the GET /api/v1/channels/{id}/members endpoint only checks membership for group and dm channel types (lines 467-469). For standard channels — including private ones — there is no channel_has_access check… | |
| Modificada | Media (5.4) | 0.27% | — | Openwebui Open Webui | 15/5/2026 | 17/6/2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the channel router does not call filter_allowed_access_grants on either create or update paths. A non-admin user who can create group channels (or who owns a channel) can submit arbitrary access grants —… | |
| Analizada | Media (4.3) | 0.30% | — | Openwebui Open Webui | 15/5/2026 | 17/6/2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the _validate_collection_access function uses an incomplete allowlist that only enforces ownership checks for collections matching user-memory-* and file-* patterns. All other collection names pass… | |
| Analizada | Alta (7.1) | 0.37% | — | Openwebui Open Webui | 15/5/2026 | 17/6/2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the /responses endpoint in the OpenAI router accepts any authenticated user and forwards requests directly to upstream LLM providers without enforcing per-model access control. While the primary chat… | |
| Analizada | Alta (7.6) | 0.35% | — | Openwebui Open Webui | 15/5/2026 | 17/6/2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, Open WebUI supports model composition via base_model_id: a user-defined model (e.g., "Cheap Assistant") can reference an existing base model (e.g., "gpt-4-turbo-restricted") that provides the actual… | |
| Analizada | Alta (8.1) | 0.43% | — | Openwebui Open Webui | 15/5/2026 | 17/6/2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the POST /api/v1/retrieval/process/web endpoint accepts a user-supplied collection_name and an overwrite query parameter (default: True). It performs no authorization check on whether the calling user… | |
| Modificada | Alta (8.1) | 0.39% | — | Openwebui Open Webui | 15/5/2026 | 17/6/2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, administrative role changes and user deletions do not iterate SESSION_POOL to disconnect affected sessions. As a result, a user whose admin role has been revoked retains admin privileges within their… | |
| Analizada | Alta (8.7) | 0.42% | — | Openwebui Open Webui | 15/5/2026 | 17/6/2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the tool_servers and terminal_servers keys in utils/tools.py do use a prefix. When two or more Open WebUI instances share a Redis database (a supported and documented deployment pattern, e.g., for… | |
| Analizada | Crítica (9.1) | 1.6% | 💥 Exploit | Openwebui Open Webui | 15/5/2026 | 17/6/2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the LDAP authentication endpoint does not validate that the submitted password is non-empty before performing a Simple Bind against the LDAP server. The LdapForm Pydantic model accepts password: str with… | |
| Analizada | Media (5) | 0.29% | — | Openwebui Open Webui | 15/5/2026 | 17/6/2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, FolderForm uses model_config = ConfigDict(extra='allow'), which permits arbitrary fields to pass through Pydantic validation and be included in model_dump(exclude_unset=True). In insert_new_folder, the… | |
| Aplazada | Media (5.1) | 0.24% | — | Savsoft QuizAI | 15/5/2026 | 17/6/2026 | Savsoft Quiz 5.0 contains a persistent cross-site scripting vulnerability in the user account settings page that allows authenticated attackers to inject malicious HTML and JavaScript code. Attackers can inject script payloads into user profile fields at the edit_user endpoint, which execute in the browsers of users… | |
| Analizada | Media (6.5) | 0.39% | — | Guimard Apache\ | 15/5/2026 | 17/6/2026 | Apache::Session::Generate::SHA256 versions before 1.3.19 for Perl create insecure session ids. Apache::Session::Generate::SHA256 generated session ids insecurely. The default session id generator returns a SHA-256 hash of the built-in rand() function, the epoch time, and the PID, that is hashed again. These are… | |
| Aplazada | Alta (7.5) | 1.2% | — | Quick PlaygroundAI | 15/5/2026 | 17/6/2026 | The Quick Playground plugin for WordPress is vulnerable to Path Traversal in versions up to and including 1.3.3. This is due to insufficient path validation in the qckply_zip_theme() function, which appends a user-controlled 'stylesheet' parameter directly to the theme root directory path without sanitizing directory… | |
| Aplazada | Media (6.9) | 0.45% | — | TuistAI | 14/5/2026 | 17/6/2026 | Tuist is a virtual platform team for Swift app devs. Prior to 1.180.10, the forgot password flow allows an unauthenticated attacker to repeatedly trigger password reset emails for a known account without server-side throttling. In self-hosted deployments, this can be abused to send large volumes of unwanted email and… | |
| Aplazada | Alta (7.1) | 0.35% | — | TuistAI | 14/5/2026 | 17/6/2026 | Tuist is a virtual platform team for Swift app devs. In 1.180.8 and earlier, the DELETE /api/projects/{account_handle}/{project_handle}/previews/{preview_id} endpoint loads the preview by its UUID without verifying that the preview belongs to the project resolved from the URL path. The route's project-level… | |
| Aplazada | Media (6.5) | 0.38% | — | TaskbuilderAI | 14/5/2026 | 17/6/2026 | The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'project_search' parameter in all versions up to, and including, 5.0.6 due to insufficient escaping on the user supplied parameter and lack of sufficient… | |
| Aplazada | Media (6.4) | 0.26% | — | Bold-themes Bold Page BuilderAI | 14/5/2026 | 17/6/2026 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the bt_bb_button shortcode in all versions up to, and including, 5.6.8. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… |