Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
CVE-2026-57233
  • github.com/notepad-plus-plus/notepad-plus-plus
  • github.com/notepad-plus-plus/wingup
Notepad++: Path Traversal (Zip Slip) in WinGup Plugin Extraction 17 Aug
  • Fix available
  • Severity - 8.1 (High)
CVE-2026-52886
  • github.com/notepad-plus-plus/notepad-plus-plus
Notepad++: session.xml backupFilePath starts_with Bypass 17 Aug
  • Fix available
  • Severity - 5.1 (Medium)
CVE-2026-71858
  • github.com/notepad-plus-plus/notepad-plus-plus
Notepad++: shortcuts.xml Macro HMAC Bypass Enables Conditional Elevated Command Execution 17 Aug
  • Fix available
  • Severity - 5.4 (Medium)
CVE-2026-54758
  • github.com/notepad-plus-plus/notepad-plus-plus
Notepad++: Stack Buffer Overflow in expandNppEnvironmentStrs 17 Aug
  • Fix available
  • Severity - 7.8 (High)
CVE-2026-73250
  • github.com/notepad-plus-plus/notepad-plus-plus
Notepad++: Install-time PowerShell command injection through installation path 11 Aug
  • Fix available
  • Severity - 5.4 (Medium)
CVE-2026-48770
  • github.com/notepad-plus-plus/notepad-plus-plus
Notepad++ WM_COPYDATA COPYDATA_FULL_CMDLINE local DoS crash 26 Jun
  • Fix available
  • Severity - 5.0 (Medium)
CVE-2026-48778
  • github.com/notepad-plus-plus/notepad-plus-plus
Notepad++: Arbitrary Code Execution via config.xml commandLineInterpreter 26 Jun
  • Fix available
  • Severity - 7.8 (High)
CVE-2026-52885
  • github.com/notepad-plus-plus/notepad-plus-plus
Notepad++ TOCTOU: HMAC Checks Disk, Executes from Memory 26 Jun
  • Fix available
  • Severity - 7.5 (High)
CVE-2026-46710
  • github.com/notepad-plus-plus/notepad-plus-plus
Notepad++: Privilege Escalation in the Installer via Uncontrolled Executable Search Path 26 Jun
  • Fix available
  • Severity - 7.5 (High)
CVE-2026-48800
  • github.com/notepad-plus-plus/notepad-plus-plus
Notepad++: Arbitrary Code Execution via shortcuts.xml UserCommand Injection 26 Jun
  • Fix available
  • Severity - 7.8 (High)
CVE-2026-52884
  • github.com/notepad-plus-plus/notepad-plus-plus
Notepad++: CVE-2026-48800 Bypass 26 Jun
  • Fix available
  • Severity - 7.8 (High)
CVE-2026-6539
  • github.com/notepad-plus-plus/notepad-plus-plus
Notepad++ 8.9.3 Format String Injection via nativeLang.xml 30 Apr
  • No fix available
  • Severity - 4.6 (Medium)
CVE-2026-5525
  • github.com/notepad-plus-plus/notepad-plus-plus
See record for full details 10 Apr
  • Fix available
  • Severity - 7.8 (High)
CVE-2026-25926
  • github.com/notepad-plus-plus/notepad-plus-plus
Notepad++ has an Untrusted Search Path 18 Feb
  • Fix available
  • Severity - 7.3 (High)
CVE-2025-15556
  • github.com/notepad-plus-plus/notepad-plus-plus
  • github.com/notepad-plus-plus/wingup
Notepad++ < 8.8.9 WinGUp Updater Lacks Update Integrity Verification 03 Feb
  • Fix available
  • Severity - 7.7 (High)
CVE-2025-49144
  • github.com/notepad-plus-plus/notepad-plus-plus
Notepad++ Privilege Escalation in Installer via Uncontrolled Executable Search Path 23 Jun 2025
  • Fix available
  • Severity - 7.3 (High)