# CVEdetails

Source: https://docs.openwebui.com/security/supply-chain-security/vulnerability-databases/cvedetails

|  |  |
| --- | --- |
| Product | CVEdetails (SecurityScorecard) |
| Records still shown as active | 9, every withdrawn identifier against Open WebUI |
| First contacted | 2026-07-23 |
| Channels tried | admin@ |
| Status | No response |

---

## Records

Every CVE that has been withdrawn against Open WebUI is still presented on CVEdetails as an active vulnerability, with a severity, a description of the impact and no rejection marker of any kind. Each identifier below is in the `REJECTED` state at [cve.org](https://www.cve.org) and at NVD:

| Identifier | Withdrawn by | Rejected since | Still live on CVEdetails | Our assessment |
| --- | --- | --- | --- | --- |
| CVE-2024-7033 | huntr / Protect AI | 2026-07-16 | cvedetails.com | Disposition |
| CVE-2024-7034 | huntr / Protect AI | 2026-07-16 | cvedetails.com | Disposition |
| CVE-2024-7038 | huntr / Protect AI | 2026-07-16 | cvedetails.com | Disposition |
| CVE-2024-7039 | huntr / Protect AI | 2026-07-16 | cvedetails.com | Disposition |
| CVE-2024-7040 | huntr / Protect AI | 2026-07-16 | cvedetails.com | Disposition |
| CVE-2024-7959 | huntr / Protect AI | 2026-07-16 | cvedetails.com | Disposition |
| CVE-2025-15603 | VulDB | 2026-06-18 | cvedetails.com | Disposition |
| CVE-2025-29446 | MITRE | 2026-06-29 | cvedetails.com | Disposition |
| CVE-2025-63391 | MITRE | 2026-06-29 | cvedetails.com | Disposition |

Three different CNAs withdrew these records, the earliest in June. A database that misses one withdrawal has a synchronisation lag. None of the nine has been updated to reflect its withdrawal, across three separate CNAs and three separate withdrawal dates.

Every row links to the live CVEdetails page next to the authoritative record, so the difference can be checked in one click.

### What those entries still tell a reader

The pages carry the original claim in full, and in two respects they present it as more serious than it was first filed.

**CVE-2024-7033** is titled "Arbitrary File Write in open-webui/open-webui" and describes overwriting critical system files, denial of service and remote code execution leading to "a full system compromise". The page carries two scores side by side: the issuing CNA's **6.5 Medium**, dated 2025-03-20, and a **7.2 High** published by NIST on 2025-07-29. Both are shown, which is correct, since NVD publishes its own assessment alongside the CNA's rather than replacing it. What is missing is the third fact, that the identifier carrying both was withdrawn on 2026-07-16. The entry was last refreshed on 2025-07-29, close to a year before that.

**CVE-2024-7959** is titled "SSRF in open-webui/open-webui", scored 7.7 High and carries an EPSS score of **24.46%, in roughly the 98th percentile**.

EPSS is produced by FIRST, not by CVEdetails, and estimates the probability that a vulnerability will see exploitation activity in the next thirty days. Vulnerability-management tooling reads it to decide what to patch first. The figure originates with FIRST. It is still being served here for an identifier that no longer exists. That entry is therefore telling every consumer of the data that there is close to a one in four chance of exploitation activity, in the coming month, against a finding whose identifier the issuing CNA withdrew on 2026-07-16, and whose stated affected version is Open WebUI 0.3.8. That release is tagged [v0.3.8](https://github.com/open-webui/open-webui/releases/tag/v0.3.8) in the project's repository, dated 2024-07-09, with 128 tagged releases published since.

Either half alone would make the figure meaningless. There is no vulnerability to exploit, and the version it would be exploited in has not been current for more than two years. A withdrawn record carrying a 98th-percentile score is shaped exactly like the input a prioritisation queue is built to promote, so it competes for attention against findings that are real.

### CVE-2025-15603 in detail

|  |  |
| --- | --- |
| Authoritative state | REJECTED at cve.org and NVD since 2026-06-18 |
| Withdrawn by | VulDB, the issuing CNA, as a false positive |
| What CVEdetails displays | An active vulnerability in open-webui, annotated "the exploit has been disclosed publicly and may be used". Page stamped "Updated 2026-04-29". |
| Our assessment | CVE-2025-15603 |

The scoring matches the CNA, so this one is purely a status problem: the page was last refreshed roughly seven weeks before the withdrawal and has not re-synced since. The added note that a public exploit exists and may be used compounds it, because that framing pushes a reader toward treating the entry as actionable.

---

## Contact log

| Date | Channel | Outcome |
| --- | --- | --- |
| 2026-07-23 | admin@ | No response |
| 2026-08-03 | admin@ | No response |
| 2026-08-08 | admin@ | No response |

As of 2026-08-08 every entry is unchanged.

---

## See also

- [Rejected CVEs in Vulnerability Databases](/security/supply-chain-security/vulnerability-databases/) — the overview and how to verify any record yourself.
- [Vendor Dispositions](/security/vendor-dispositions) — our assessment of each identifier listed above.
