Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
CVE-2026-85995
  • github.com/notepad-plus-plus/notepad-plus-plus
Notepad++: Authenticode verification bypass allows modified updater execution 22 Sep
  • Fix available
  • Severity - 7.3 (High)
CVE-2026-86056
  • github.com/notepad-plus-plus/notepad-plus-plus
Notepad++: Null pointer dereference in NPPM_SAVESESSION message handler causes crash (DoS) 22 Sep
  • Fix available
  • Severity - 5.5 (Medium)
CVE-2026-77605
  • github.com/notepad-plus-plus/notepad-plus-plus
Notepad++ “Run by system” executes *.txt.cmd when user selected *.txt (target confusion → command execution) 22 Sep
  • Fix available
  • Severity - 7.8 (High)
CVE-2026-86054
  • github.com/notepad-plus-plus/notepad-plus-plus
Notepad++: Stack Buffer Overflow in `NppParameters::writeSession` via overlong session path 22 Sep
  • Fix available
  • Severity - 7.8 (High)
CVE-2026-85288
  • github.com/notepad-plus-plus/notepad-plus-plus
Notepad++: Shortcuts.xml macro HMAC bypass still reachable via the "Run a Macro Multiple Times" dialog 22 Sep
  • Fix available
  • Severity - 6.7 (Medium)
CVE-2026-85279
  • github.com/notepad-plus-plus/notepad-plus-plus
Notepad++: Stack Buffer Overflow in Plugin Lexer Loading via Unchecked GetLexerCount() Return Value 22 Sep
  • Fix available
  • Severity - 8.6 (High)
CVE-2026-57233
  • github.com/notepad-plus-plus/notepad-plus-plus
  • github.com/notepad-plus-plus/wingup
Notepad++: Path Traversal (Zip Slip) in WinGup Plugin Extraction 17 Aug
  • Fix available
  • Severity - 8.1 (High)
CVE-2026-52886
  • github.com/notepad-plus-plus/notepad-plus-plus
Notepad++: session.xml backupFilePath starts_with Bypass 17 Aug
  • Fix available
  • Severity - 5.1 (Medium)
CVE-2026-71858
  • github.com/notepad-plus-plus/notepad-plus-plus
Notepad++: shortcuts.xml Macro HMAC Bypass Enables Conditional Elevated Command Execution 17 Aug
  • Fix available
  • Severity - 5.4 (Medium)
CVE-2026-54758
  • github.com/notepad-plus-plus/notepad-plus-plus
Notepad++: Stack Buffer Overflow in expandNppEnvironmentStrs 17 Aug
  • Fix available
  • Severity - 7.8 (High)
CVE-2026-73250
  • github.com/notepad-plus-plus/notepad-plus-plus
Notepad++: Install-time PowerShell command injection through installation path 11 Aug
  • Fix available
  • Severity - 5.4 (Medium)
CVE-2026-48770
  • github.com/notepad-plus-plus/notepad-plus-plus
Notepad++ WM_COPYDATA COPYDATA_FULL_CMDLINE local DoS crash 26 Jun
  • Fix available
  • Severity - 5.0 (Medium)
CVE-2026-48778
  • github.com/notepad-plus-plus/notepad-plus-plus
Notepad++: Arbitrary Code Execution via config.xml commandLineInterpreter 26 Jun
  • Fix available
  • Severity - 7.8 (High)
CVE-2026-52885
  • github.com/notepad-plus-plus/notepad-plus-plus
Notepad++ TOCTOU: HMAC Checks Disk, Executes from Memory 26 Jun
  • Fix available
  • Severity - 7.5 (High)
CVE-2026-46710
  • github.com/notepad-plus-plus/notepad-plus-plus
Notepad++: Privilege Escalation in the Installer via Uncontrolled Executable Search Path 26 Jun
  • Fix available
  • Severity - 7.5 (High)
CVE-2026-48800
  • github.com/notepad-plus-plus/notepad-plus-plus
Notepad++: Arbitrary Code Execution via shortcuts.xml UserCommand Injection 26 Jun
  • Fix available
  • Severity - 7.8 (High)