What is CVE-2026-87995?
CVE-2026-87995 is a vulnerability classified as Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') and Improper Restriction of Rendered UI Layers or Frames, affecting open-webui (affected versions: >= 0.8.11, < 0.11.1). This vulnerability is rated High, with a CVSS score of 8.7. There is not enough data to determine whether this vulnerability has been exploited.