# Vulmon Source: https://docs.openwebui.com/security/supply-chain-security/vulnerability-databases/vulmon | | | | --- | --- | | Product | Vulmon Search | | Records still shown as active | 9, every withdrawn identifier against Open WebUI | | First contacted | 2026-07-23 | | Channels tried | info@ | | Status | No response | --- ## Records Every CVE withdrawn against Open WebUI still has a live Vulmon page presenting it as a vulnerability, with a summary, a severity, Vulmon's own derived scores and no rejection marker. Each identifier below is in the `REJECTED` state at [cve.org](https://www.cve.org) and at NVD: | Identifier | Withdrawn by | Rejected since | Still live on Vulmon | Our assessment | | --- | --- | --- | --- | --- | | CVE-2024-7033 | huntr / Protect AI | 2026-07-16 | vulmon.com | Disposition | | CVE-2024-7034 | huntr / Protect AI | 2026-07-16 | vulmon.com | Disposition | | CVE-2024-7038 | huntr / Protect AI | 2026-07-16 | vulmon.com | Disposition | | CVE-2024-7039 | huntr / Protect AI | 2026-07-16 | vulmon.com | Disposition | | CVE-2024-7040 | huntr / Protect AI | 2026-07-16 | vulmon.com | Disposition | | CVE-2024-7959 | huntr / Protect AI | 2026-07-16 | vulmon.com | Disposition | | CVE-2025-15603 | VulDB | 2026-06-18 | vulmon.com | Disposition | | CVE-2025-29446 | MITRE | 2026-06-29 | vulmon.com | Disposition | | CVE-2025-63391 | MITRE | 2026-06-29 | vulmon.com | Disposition | ### Derived scores on withdrawn records Vulmon computes its own figures from the record it mirrors. Each of these pages carries a **VMScore** and an EPSS value alongside the CVSS, presented as current risk data. **CVE-2025-63391** shows CVSS 7.5 and a VMScore of **850**, with a summary stating that unauthenticated remote attackers can retrieve critical configuration data without valid credentials. That claim is [wrong on the code](/security/vendor-dispositions/cve-2025-63391), and the identifier making it was withdrawn on 2026-06-29. The page was last updated on 2025-12-19, six months before the withdrawal. **CVE-2025-29446** shows CVSS 3.3 and a VMScore of **430**. It was last updated on 2025-05-28, more than a year before the withdrawal. A score computed from a withdrawn record is a number with nothing behind it. It is still presented in the same place, in the same format, as a score for a live finding. --- ## Contact log | Date | Channel | Outcome | | --- | --- | --- | | 2026-07-23 | info@ | No response | | 2026-08-03 | info@ | No response | | 2026-08-08 | info@ | No response | As of 2026-08-08 every entry is unchanged. --- ## See also - [Rejected CVEs in Vulnerability Databases](/security/supply-chain-security/vulnerability-databases/) — the overview and how to verify any record yourself. - [Vendor Dispositions](/security/vendor-dispositions) — our assessment of each identifier listed above.