Evan Chan
5 exploits
Active since Dec 2025
NiceGUI <3.10.0 Windows Upload Filename - Path Traversal
CVSS 5.9
NiceGUI's unvalidated chunk size parameter in media routes can cause memory exhaustion
CVSS 7.5
NiceGUI < 3.4.0 - Reflected Cross-Site Scripting via CSS/SCSS/SASS Injection
CVSS 6.1
NiceGUI < 3.4.0 - Path Traversal via App.add_media_files()
CVSS 7.5
NiceGUI < 3.7.0 - Stored Cross-Site Scripting via ui.markdown() Component
CVSS 6.1