Zauberzeug's vulnerability profile centers on NiceGUI, a modestly represented Python web framework for building graphical interfaces. The framework's exposure recurs through application-layer and resource-management weakness classes including cross-site scripting, path traversal, input validation flaws, and resource-exhaustion conditions that are characteristic of web-facing UI libraries. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zauberzeug over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-25732HIGH NiceGUI is a Python-based UI framework. Prior to 3.7.0, NiceGUI's FileUpload.name property exposes client-supplied filename metadata without sanitization, enabling path traversal w | Feb 6, 2026 | 7.5 | 37 | NO | YES |
CVE-2026-39844HIGH NiceGUI is a Python-based UI framework. Prior to 3.10.0, Since PurePosixPath only recognizes forward slashes (/) as path separators, an attacker can bypass this sanitization on Win | Apr 8, 2026 | 7.5 | 32 | NO | NO |
CVE-2025-66645HIGH NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are vulnerable to directory traversal through the App.add_media_files() function, which allows a remote attacker t | Dec 9, 2025 | 7.5 | 24 | NO | NO |
CVE-2026-33332HIGH NiceGUI is a Python-based UI framework. Prior to version 3.9.0, NiceGUI's app.add_media_file() and app.add_media_files() media routes accept a user-controlled query parameter that | Mar 24, 2026 | 7.5 | 22 | NO | NO |
CVE-2026-27156MEDIUM NiceGUI is a Python-based UI framework. Prior to version 3.8.0, several NiceGUI APIs that execute methods on client-side elements (`Element.run_method()`, `AgGrid.run_grid_method() | Feb 24, 2026 | 6.1 | 22 | NO | NO |
CVE-2025-66470MEDIUM NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are subject to a XSS vulnerability through the ui.interactive_image component of NiceGUI. The component renders SVG | Dec 9, 2025 | 6.1 | 22 | NO | NO |
CVE-2026-25516MEDIUM NiceGUI is a Python-based UI framework. The ui.markdown() component uses the markdown2 library to convert markdown content to HTML, which is then rendered via innerHTML. By default | Feb 6, 2026 | 6.1 | 21 | NO | NO |
CVE-2026-21872MEDIUM NiceGUI is a Python-based UI framework. From versions 2.22.0 to 3.4.1, an unsafe implementation in the click event listener used by ui.sub_pages, combined with attacker-controlled | Jan 8, 2026 | 6.1 | 21 | NO | NO |
CVE-2026-21871MEDIUM NiceGUI is a Python-based UI framework. From versions 2.13.0 to 3.4.1, there is a XSS risk in NiceGUI when developers pass attacker-controlled strings into ui.navigate.history.push | Jan 8, 2026 | 6.1 | 21 | NO | NO |
CVE-2025-66469MEDIUM NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are vulnerable to Reflected XSS through its ui.add_css, ui.add_scss, and ui.add_sass functions. The functions lack | Dec 9, 2025 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zauberzeug.
Media articles that mention a CVE ID that affects a product developed by Zauberzeug — matched by CVE ID, not by vendor name.