# Vulmon

Source: https://docs.openwebui.com/security/supply-chain-security/vulnerability-databases/vulmon

|  |  |
| --- | --- |
| Product | Vulmon Search |
| Records still shown as active | 9, every withdrawn identifier against Open WebUI |
| First contacted | 2026-07-23 |
| Channels tried | info@ |
| Status | No response |

---

## Records

Every CVE withdrawn against Open WebUI still has a live Vulmon page presenting it as a vulnerability, with a summary, a severity, Vulmon's own derived scores and no rejection marker. Each identifier below is in the `REJECTED` state at [cve.org](https://www.cve.org) and at NVD:

| Identifier | Withdrawn by | Rejected since | Still live on Vulmon | Our assessment |
| --- | --- | --- | --- | --- |
| CVE-2024-7033 | huntr / Protect AI | 2026-07-16 | vulmon.com | Disposition |
| CVE-2024-7034 | huntr / Protect AI | 2026-07-16 | vulmon.com | Disposition |
| CVE-2024-7038 | huntr / Protect AI | 2026-07-16 | vulmon.com | Disposition |
| CVE-2024-7039 | huntr / Protect AI | 2026-07-16 | vulmon.com | Disposition |
| CVE-2024-7040 | huntr / Protect AI | 2026-07-16 | vulmon.com | Disposition |
| CVE-2024-7959 | huntr / Protect AI | 2026-07-16 | vulmon.com | Disposition |
| CVE-2025-15603 | VulDB | 2026-06-18 | vulmon.com | Disposition |
| CVE-2025-29446 | MITRE | 2026-06-29 | vulmon.com | Disposition |
| CVE-2025-63391 | MITRE | 2026-06-29 | vulmon.com | Disposition |

### Derived scores on withdrawn records

Vulmon computes its own figures from the record it mirrors. Each of these pages carries a **VMScore** and an EPSS value alongside the CVSS, presented as current risk data.

**CVE-2025-63391** shows CVSS 7.5 and a VMScore of **850**, with a summary stating that unauthenticated remote attackers can retrieve critical configuration data without valid credentials. That claim is [wrong on the code](/security/vendor-dispositions/cve-2025-63391), and the identifier making it was withdrawn on 2026-06-29. The page was last updated on 2025-12-19, six months before the withdrawal.

**CVE-2025-29446** shows CVSS 3.3 and a VMScore of **430**. It was last updated on 2025-05-28, more than a year before the withdrawal.

A score computed from a withdrawn record is a number with nothing behind it. It is still presented in the same place, in the same format, as a score for a live finding.

---

## Contact log

| Date | Channel | Outcome |
| --- | --- | --- |
| 2026-07-23 | info@ | No response |
| 2026-08-03 | info@ | No response |
| 2026-08-08 | info@ | No response |

As of 2026-08-08 every entry is unchanged.

---

## See also

- [Rejected CVEs in Vulnerability Databases](/security/supply-chain-security/vulnerability-databases/) — the overview and how to verify any record yourself.
- [Vendor Dispositions](/security/vendor-dispositions) — our assessment of each identifier listed above.
