Zauberzeug
Zauberzeug Nicegui: vulnerabilidades y CVE
Zauberzeug Nicegui tiene 17 vulnerabilidades publicadas, 15 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE17
Últimos 12 meses15
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-45554 | Media (5.3) | 0.60% | — | 2 jun 2026 | NiceGUI is a Python-based UI framework. Prior to version 3.12.0, two FastAPI routes that serve per-component static assets in NiceGUI accept a sub-path parameter that may resolve to a directory rather than a file.… |
| CVE-2026-45553 | Alta (7.5) | 0.43% | — | 2 jun 2026 | NiceGUI is a Python-based UI framework. Prior to version 3.12.0, ui.restructured_text() renders reStructuredText server-side with Docutils without disabling file insertion directives. When a NiceGUI application passes… |
| CVE-2026-39844 | Alta (7.5) | 0.49% | — | 8 abr 2026 | NiceGUI is a Python-based UI framework. Prior to 3.10.0, Since PurePosixPath only recognizes forward slashes (/) as path separators, an attacker can bypass this sanitization on Windows by using backslashes (\) in the… |
| CVE-2026-33332 | Media (6.9) | 0.69% | — | 24 mar 2026 | NiceGUI is a Python-based UI framework. Prior to version 3.9.0, NiceGUI's app.add_media_file() and app.add_media_files() media routes accept a user-controlled query parameter that influences how files are read during… |
| CVE-2026-27156 | Media (6.1) | 0.27% | — | 24 feb 2026 | NiceGUI is a Python-based UI framework. Prior to version 3.8.0, several NiceGUI APIs that execute methods on client-side elements (`Element.run_method()`, `AgGrid.run_grid_method()`, `EChart.run_chart_method()`, and… |
| CVE-2026-25732 | Alta (7.5) | 3.0% | — | 6 feb 2026 | NiceGUI is a Python-based UI framework. Prior to 3.7.0, NiceGUI's FileUpload.name property exposes client-supplied filename metadata without sanitization, enabling path traversal when developers use the pattern… |
| CVE-2026-25516 | Media (6.1) | 0.29% | — | 6 feb 2026 | NiceGUI is a Python-based UI framework. The ui.markdown() component uses the markdown2 library to convert markdown content to HTML, which is then rendered via innerHTML. By default, markdown2 allows raw HTML to pass… |
| CVE-2026-21874 | Media (5.3) | 0.56% | — | 8 ene 2026 | NiceGUI is a Python-based UI framework. From versions v2.10.0 to 3.4.1, an unauthenticated attacker can exhaust Redis connections by repeatedly opening and closing browser tabs on any NiceGUI application using… |
| CVE-2026-21873 | Media (6.1) | 0.26% | — | 8 ene 2026 | NiceGUI is a Python-based UI framework. From versions 2.22.0 to 3.4.1, an unsafe implementation in the pushstate event listener used by ui.sub_pages allows an attacker to manipulate the fragment identifier of the URL,… |
| CVE-2026-21872 | Media (6.1) | 0.27% | — | 8 ene 2026 | NiceGUI is a Python-based UI framework. From versions 2.22.0 to 3.4.1, an unsafe implementation in the click event listener used by ui.sub_pages, combined with attacker-controlled link rendering on the page, causes XSS… |
| CVE-2026-21871 | Media (6.1) | 0.28% | — | 8 ene 2026 | NiceGUI is a Python-based UI framework. From versions 2.13.0 to 3.4.1, there is a XSS risk in NiceGUI when developers pass attacker-controlled strings into ui.navigate.history.push() or ui.navigate.history.replace().… |
| CVE-2025-66645 | Alta (7.5) | 1.1% | — | 9 dic 2025 | NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are vulnerable to directory traversal through the App.add_media_files() function, which allows a remote attacker to read arbitrary files on the server… |
| CVE-2025-66470 | Media (6.1) | 0.25% | — | 9 dic 2025 | NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are subject to a XSS vulnerability through the ui.interactive_image component of NiceGUI. The component renders SVG content using Vue's v-html directive… |
| CVE-2025-66469 | Media (6.1) | 0.27% | — | 9 dic 2025 | NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are vulnerable to Reflected XSS through its ui.add_css, ui.add_scss, and ui.add_sass functions. The functions lack proper sanitization or encoding for the… |
| CVE-2025-53354 | Media (6.1) | 0.20% | — | 3 oct 2025 | NiceGUI is a Python-based UI framework. Versions 2.24.2 and below are at risk for Cross-Site Scripting (XSS) when developers render unescaped user input into the DOM using ui.html(). NiceGUI did not enforce HTML or… |
| CVE-2025-21618 | Alta (7.5) | 0.38% | — | 6 ene 2025 | NiceGUI is an easy-to-use, Python-based UI framework. Prior to 2.9.1, authenticating with NiceGUI logged in the user for all browsers, including browsers in incognito mode. This vulnerability is fixed in 2.9.1. |
| CVE-2024-32005 | Alta (8.2) | 0.76% | — | 12 abr 2024 | NiceGUI is an easy-to-use, Python-based UI framework. A local file inclusion is present in the NiceUI leaflet component when requesting resource files under the `/_nicegui/{__version__}/resources/{key}/{path:path}`… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.