← Back

Notepad Plus Plus

notepad-plus-plus

13 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Notepad++
notepad++

CVEs (13)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Notepad Plus Plus
1Notepad++
May 1, 2026
Apr 30, 2026
4.6 MEDIUM· v4
4.4 MEDIUM· v3
N/A· v2
Notepad++ 8.9.3 contains a format string injection vulnerability in the Find Results panel handler that allows attackers to cause denial of service and information disclosure by crafting a malicious nativeLang.xml langua...Show more
Notepad++ 8.9.3 contains a format string injection vulnerability in the Find Results panel handler that allows attackers to cause denial of service and information disclosure by crafting a malicious nativeLang.xml language pack file. Attackers can distribute a poisoned language pack through community channels that triggers format string interpretation when a user performs search operations, leading to access violations and potential leakage of stack or register contents.Show less
1Notepad Plus Plus
1Notepad++
Feb 19, 2026
Feb 19, 2026
N/A· v4
7.3 HIGH· v3
N/A· v2
Notepad++ is a free and open-source source code editor. An Unsafe Search Path vulnerability (CWE-426) exists in versions prior to 8.9.2 when launching Windows Explorer without an absolute executable path. This may allow...Show more
Notepad++ is a free and open-source source code editor. An Unsafe Search Path vulnerability (CWE-426) exists in versions prior to 8.9.2 when launching Windows Explorer without an absolute executable path. This may allow execution of a malicious explorer.exe if an attacker can control the process working directory. Under certain conditions, this could lead to arbitrary code execution in the context of the running application. Version 8.9.2 patches the issue.Show less
1Notepad Plus Plus
1Notepad++
Feb 13, 2026
Feb 3, 2026
7.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability where downloaded update metadata and installers are not cryptographically verified. An attacker abl...Show more
Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability where downloaded update metadata and installers are not cryptographically verified. An attacker able to intercept or redirect update traffic can cause the updater to download and execute an attacker-controlled installer, resulting in arbitrary code execution with the privileges of the user.Show less
1Notepad Plus Plus
1Notepad++
Nov 21, 2024
Nov 30, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
An Untrusted search path vulnerability in notepad++ 6.5 allows local users to gain escalated privileges through the msimg32.dll file in the current working directory.
1Notepad Plus Plus
1Notepad++
Nov 21, 2024
Nov 30, 2023
N/A· v4
7.8 HIGH· v3
4.3 MEDIUM· v2
A vulnerability classified as problematic was found in NotePad++ up to 8.1. Affected by this vulnerability is an unknown functionality of the file dbghelp.exe. The manipulation leads to uncontrolled search path. An attac...Show more
A vulnerability classified as problematic was found in NotePad++ up to 8.1. Affected by this vulnerability is an unknown functionality of the file dbghelp.exe. The manipulation leads to uncontrolled search path. An attack has to be approached locally. The identifier VDB-246421 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Notepad Plus Plus
1Notepad++
Nov 21, 2024
Aug 25, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to heap buffer read overflow in `FileManager::detectLanguageFromTextBegining `. The exploitability of this issue is not clea...Show more
Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to heap buffer read overflow in `FileManager::detectLanguageFromTextBegining `. The exploitability of this issue is not clear. Potentially, it may be used to leak internal memory allocation information. As of time of publication, no known patches are available in existing versions of Notepad++.Show less
1Notepad Plus Plus
1Notepad++
Nov 21, 2024
Aug 25, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to global buffer read overflow in `nsCodingStateMachine::NextStater`. The exploitability of this issue is not clear. Potenti...Show more
Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to global buffer read overflow in `nsCodingStateMachine::NextStater`. The exploitability of this issue is not clear. Potentially, it may be used to leak internal memory allocation information. As of time of publication, no known patches are available in existing versions of Notepad++.Show less
1Notepad Plus Plus
1Notepad++
Nov 21, 2024
Aug 25, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to global buffer read overflow in `CharDistributionAnalysis::HandleOneChar`. The exploitability of this issue is not clear....Show more
Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to global buffer read overflow in `CharDistributionAnalysis::HandleOneChar`. The exploitability of this issue is not clear. Potentially, it may be used to leak internal memory allocation information. As of time of publication, no known patches are available in existing versions of Notepad++.Show less
1Notepad Plus Plus
1Notepad++
Nov 21, 2024
Aug 25, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to heap buffer write overflow in `Utf8_16_Read::convert`. This issue may lead to arbitrary code execution. As of time of pub...Show more
Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to heap buffer write overflow in `Utf8_16_Read::convert`. This issue may lead to arbitrary code execution. As of time of publication, no known patches are available in existing versions of Notepad++.Show less
1Notepad Plus Plus
1Notepad++
Mar 27, 2025
Feb 1, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Notepad++ v8.4.1 was discovered to contain a stack overflow via the component Finder::add().
1Notepad Plus Plus
1Notepad++
Apr 4, 2025
Jan 19, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Buffer overflow in function Notepad_plus::addHotSpot in Notepad++ v8.4.3 and earlier allows attackers to crash the application via two crafted files.
1Notepad Plus Plus
1Notepad++
May 21, 2025
Sep 28, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Notepad++ versions 8.4.1 and before are vulnerable to DLL hijacking where an attacker can replace the vulnerable dll (UxTheme.dll) with his own dll and run arbitrary code in the context of Notepad++.
2Notepad Plus Plus
Scintilla
2Notepad++
Scintilla
Nov 21, 2024
Sep 14, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafted .ml file.