Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2242845
AlmaLinux
5975
Alpaquita
16181
Alpine
4655
Android
3708
Azure Linux
17971
BellSoft Hardened Containers
771
Bitnami
9501
Chainguard
1048720
CleanStart
5479
CRAN
14
crates.io
2768
Debian
68994
Echo
7855
GHC
3
GIT
109121
GitHub Actions
55
Go
9332
Hackage
33
Hex
365
Julia
1713
Linux
29975
Mageia
6237
Maven
7055
MinimOS
148659
npm
229272
NuGet
1869
opam
29
openEuler
8900
openSUSE
14647
OSS-Fuzz
4019
Packagist
7103
Pub
11
PyPI
25495
Red Hat
23535
Rocky Linux
4354
Root
19655
RubyGems
5369
SUSE
23455
SwiftURL
61
TuxCare
9977
Ubuntu
66090
VSCode
21
Wolfi
293843
ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-2680
PyPI/nicegui
NiceGUI: Unauthenticated log-volume denial of service in dynamic resource routes
13 Jul
Fix available
Severity - 5.3 (Medium)
PYSEC-2026-2679
PyPI/nicegui
NiceGUI: Local file disclosure via Docutils file insertion in ui.restructured_text()
13 Jul
Fix available
Severity - 7.5 (High)
PYSEC-2026-1703
PyPI/nicegui
NiceGUI has Redis connection leak via tab storage causes service degradation
07 Jul
Fix available
Severity - 5.3 (Medium)
PYSEC-2026-1702
PyPI/nicegui
NiceGUI apps which use `ui.sub_pages` vulnerable to zero-click XSS
07 Jul
Fix available
Severity - 7.2 (High)
PYSEC-2026-1701
PyPI/nicegui
NiceGUI apps are vulnerable to XSS which uses `ui.sub_pages` and render arbitrary user-provided links
07 Jul
Fix available
Severity - 6.1 (Medium)
PYSEC-2026-1698
PyPI/nicegui
NiceGUI is vulnerable to XSS via Unescaped URL in ui.navigate.history.push() / replace()
07 Jul
Fix available
Severity - 6.1 (Medium)
PYSEC-2026-1700
PyPI/nicegui
NiceGUI has a path traversal in app.add_media_files() allows arbitrary file read
07 Jul
Fix available
Severity - 7.5 (High)
PYSEC-2026-1696
PyPI/nicegui
NiceGUI Stored/Reflected XSS in ui.interactive_image via unsanitized SVG content
07 Jul
Fix available
Severity - 6.1 (Medium)
PYSEC-2026-1697
PyPI/nicegui
NiceGUI Reflected XSS in ui.add_css, ui.add_scss, and ui.add_sass via Style Injection
07 Jul
Fix available
Severity - 6.1 (Medium)
PYSEC-2026-1699
PyPI/nicegui
NiceGUI has a Reflected XSS
07 Jul
Fix available
Severity - 6.1 (Medium)
PYSEC-2026-1705
PyPI/nicegui
NiceGUI On Air authentication issue
07 Jul
Fix available
Severity - 7.5 (High)
PYSEC-2026-1704
PyPI/nicegui
NiceGUI allows potential access to local file system
07 Jul
Fix available
Severity - 8.2 (High)
GHSA-pq7c-x8g4-rvp6
PyPI/nicegui
NiceGUI: Unauthenticated log-volume denial of service in dynamic resource routes
18 May
Fix available
Severity - 5.3 (Medium)
GHSA-jfrm-rx66-g536
PyPI/nicegui
NiceGUI: Local file disclosure via Docutils file insertion in ui.restructured_text()
18 May
Fix available
Severity - 7.5 (High)
PYSEC-2026-2234
PyPI/nicegui
See record for full details
08 Apr
Fix available
Severity - 7.5 (High)
GHSA-w8wv-vfpc-hw2w
PyPI/nicegui
NiceGUI: Upload filename sanitization bypass via backslashes allows path traversal on Windows
08 Apr
Fix available
Severity - 5.9 (Medium)
Load more...
PyPI - OSV