Skip to main content

Vendor/product archive

notepad-plus-plus / notepad++ CVEs

Beta · best-effort

21 CVEs tagged to notepad-plus-plus / notepad++0 Critical, 12 High, 9 Medium, 0 Low, 0 Unrated.

CVE-2026-52885

Published Jun 26, 2026

Notepad++ is a free and open-source source code editor. Prior to 8.9.6.4, NppCommands.cpp checks the HMAC of the on-disk shortcuts.xml at the moment a user command fires (Time-of-…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-52884

Published Jun 26, 2026

Notepad++ is a free and open-source source code editor. In v8.9.6.1, isInTrustedDirectory() does NOT canonicalize the path before checking. It uses a prefix-based check (PathIsPre…

CVSS 7.8 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-48800

Published Jun 26, 2026

Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, the <Command> tag text content inside <UserDefinedCommands> in shortcuts.xml is read by NppXml::value(aNo…

CVSS 7.8 · High
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2026-48778

Published Jun 26, 2026

Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, the <GUIConfig name="commandLineInterpreter"> tag in config.xml is read by NppXml::value() (Parameters.cp…

CVSS 7.8 · High
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2026-48770

Published Jun 26, 2026

Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, a local process in the same interactive Windows session can send a malformed WM_COPYDATA message to Notep…

CVSS 5.0 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-46710

Published Jun 26, 2026

Notepad++ is a free and open-source source code editor. From 8.9.4 until 8.9.6, Notepad++ contains a local privilege escalation vulnerability in the installer. During installation…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-6539

Published Apr 30, 2026

Notepad++ 8.9.3 contains a format string injection vulnerability in the Find Results panel handler that allows attackers to cause denial of service and information disclosure by c…

CVSS 4.6 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-5525

Published Apr 10, 2026

A stack-based buffer overflow vulnerability exists in Notepad++ version 8.9.3 in the file drop handler component. When a user drags and drops a directory path of exactly 259 chara…

CVSS 6.0 · Medium
evidence mentions
3
Buzz score
23.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-25926

Published Feb 19, 2026

Notepad++ is a free and open-source source code editor. An Unsafe Search Path vulnerability (CWE-426) exists in versions prior to 8.9.2 when launching Windows Explorer without an…

CVSS 7.3 · High
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2025-15556

Published Feb 3, 2026

Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability where downloaded update metadata and installers are not cr…

CVSS 7.7 · High
evidence mentions
9
Buzz score
68.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2023-47452

Published Nov 30, 2023

An Untrusted search path vulnerability in notepad++ 6.5 allows local users to gain escalated privileges through the msimg32.dll file in the current working directory.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-6401

Published Nov 30, 2023

A vulnerability classified as problematic was found in NotePad++ up to 8.1. Affected by this vulnerability is an unknown functionality of the file dbghelp.exe. The manipulation le…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40166

Published Aug 25, 2023

Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to heap buffer read overflow in `FileManager::detectLanguageFromTextBegining `. The…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40164

Published Aug 25, 2023

Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to global buffer read overflow in `nsCodingStateMachine::NextStater`. The exploitab…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40036

Published Aug 25, 2023

Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to global buffer read overflow in `CharDistributionAnalysis::HandleOneChar`. The ex…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40031

Published Aug 25, 2023

Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to heap buffer write overflow in `Utf8_16_Read::convert`. This issue may lead to ar…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31901

Published Jan 19, 2023

Buffer overflow in function Notepad_plus::addHotSpot in Notepad++ v8.4.3 and earlier allows attackers to crash the application via two crafted files.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-32168

Published Sep 28, 2022

Notepad++ versions 8.4.1 and before are vulnerable to DLL hijacking where an attacker can replace the vulnerable dll (UxTheme.dll) with his own dll and run arbitrary code in the c…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-21 of 21 CVEsPage 1 of 1