notepad-plus-plus records
21 published records for vendor notepad-plus-plus.
Researcher profile
- Entered KEV
- 1 · 4.8%
- Weaponized
- 1 · 4.8%
- Pre-auth RCE
- 1
- With a fix record
- 38.1%
- Median publish → KEV
- 10 days
Recurring classes
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')4
- CWE-427 Uncontrolled Search Path Element3
- CWE-787 Out-of-bounds Write3
- CWE-426 Untrusted Search Path2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
The weakness classes this vendor ships most often: where to look.
CWEAll records
21 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
61This week | CVE-2025-15556Weaponized | Notepad++ < 8.8.9 WinGUp Updater Lacks Update Integrity Verificationnotepad-plus-plus · notepad\+\+ · CWE-494 | High7.7 | KEV | 1.8% | Feb 2, 2026 |
34Monitor | CVE-2019-16294Proof of concept | SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a craftescintilla · scintilla · CWE-787 | High7.8 | — | 9.8% | Sep 14, 2019 |
31Monitor | CVE-2017-8803No exploit | Notepad++ 7.3.3 (32-bit) with Hex Editor Plugin v0.9.5 might allow user-assisted attackers to execute code via a crafted file, because of a mh-nexus · hex editor · CWE-119 | High7.8 | — | 1.6% | Jul 5, 2017 |
31Monitor | CVE-2022-32168No exploit | notepad-plus-plus - DLL Hijackingnotepad-plus-plus · notepad\+\+ · CWE-427 | High7.8 | — | 0.8% | Sep 28, 2022 |
31Monitor | CVE-2026-48778Proof of concept | Notepad++: Arbitrary Code Execution via config.xml commandLineInterpreternotepad-plus-plus · notepad\+\+ · CWE-78 | High7.8 | — | 0.6% | Jun 26, 2026 |
31Monitor | CVE-2023-47452No exploit | An Untrusted search path vulnerability in notepad++ 6.5 allows local users to gain escalated privileges through the msimg32.dll file in the notepad-plus-plus · notepad\+\+ · CWE-427 | High7.8 | — | 0.5% | Nov 30, 2023 |
31Monitor | CVE-2023-40031Proof of concept | Notepad++ vulnerable to heap buffer write overflow in Utf8_16_Read::convertnotepad-plus-plus · notepad\+\+ · CWE-120 | High7.8 | — | 0.5% | Aug 25, 2023 |
31Monitor | CVE-2023-6401Proof of concept | NotePad++ dbghelp.exe uncontrolled search pathnotepad-plus-plus · notepad\+\+ · CWE-427 | High7.8 | — | 0.3% | Nov 30, 2023 |
31Monitor | CVE-2026-48800Proof of concept | Notepad++: Arbitrary Code Execution via shortcuts.xml UserCommand Injectionnotepad-plus-plus · notepad\+\+ · CWE-78 | High7.8 | — | 0.2% | Jun 26, 2026 |
31Monitor | CVE-2026-52884No exploit | Notepad++: CVE-2026-48800 Bypassnotepad-plus-plus · notepad\+\+ · CWE-42 | High7.8 | — | 0.2% | Jun 26, 2026 |
31Monitor | CVE-2026-5525No exploit | Stack-Based Buffer Overflow in Notepad++ File Drop Handler leads to DoSnotepad-plus-plus · notepad\+\+ · CWE-121 | High7.8 | — | 0.2% | Apr 10, 2026 |
30Monitor | CVE-2026-46710No exploit | Notepad++: Privilege Escalation in the Installer via Uncontrolled Executable Search Pathnotepad-plus-plus · notepad\+\+ · CWE-426 | High7.5 | — | 0.2% | Jun 26, 2026 |
30Monitor | CVE-2026-52885Proof of concept | Notepad++ TOCTOU: HMAC Checks Disk, Executes from Memorynotepad-plus-plus · notepad\+\+ · CWE-367 | High7.5 | — | 0.1% | Jun 26, 2026 |
29Monitor | CVE-2026-25926No exploit | Notepad++ has an Untrusted Search Pathnotepad-plus-plus · notepad\+\+ · CWE-426 | High7.3 | — | 0.2% | Feb 18, 2026 |
26Monitor | CVE-2022-31901Proof of concept | Buffer overflow in function Notepad_plus::addHotSpot in Notepad++ v8.4.3 and earlier allows attackers to crash the application via two craftnotepad-plus-plus · notepad\+\+ · CWE-787 | Medium6.5 | — | 1.3% | Jan 19, 2023 |
22Monitor | CVE-2022-31902Proof of concept | Notepad++ v8.4.1 was discovered to contain a stack overflow via the component Finder::add().notepad-plus-plus · notepad\+\+ · CWE-787 | Medium5.5 | — | 0.5% | Jan 31, 2023 |
22Monitor | CVE-2023-40164No exploit | Notepad++ global buffer read overflow in nsCodingStateMachine::NextStatenotepad-plus-plus · notepad\+\+ · CWE-120 | Medium5.5 | — | 0.5% | Aug 25, 2023 |
22Monitor | CVE-2023-40166No exploit | Notepad++ heap buffer read overflow in FileManager::detectLanguageFromTextBeginingnotepad-plus-plus · notepad\+\+ · CWE-120 | Medium5.5 | — | 0.4% | Aug 25, 2023 |
22Monitor | CVE-2023-40036No exploit | Notepad++ global buffer read overflow in CharDistributionAnalysis::HandleOneCharnotepad-plus-plus · notepad\+\+ · CWE-120 | Medium5.5 | — | 0.4% | Aug 25, 2023 |
20Monitor | CVE-2026-48770Proof of concept | Notepad++ WM_COPYDATA COPYDATA_FULL_CMDLINE local DoS crashnotepad-plus-plus · notepad\+\+ · CWE-125 | Medium5.0 | — | 0.1% | Jun 26, 2026 |
18Monitor | CVE-2026-6539No exploit | Notepad++ 8.9.3 Format String Injection via nativeLang.xmlnotepad-plus-plus · notepad\+\+ · CWE-134 | Medium4.6 | — | 0.2% | Apr 30, 2026 |
- CVE-2025-1555661This week
Notepad++ < 8.8.9 WinGUp Updater Lacks Update Integrity Verification
HighCVSS 7.7KEVWeaponizedEPSS 2%notepad-plus-plus · notepad\+\+Feb 2, 2026
- CVE-2019-1629434Monitor
SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafte
HighCVSS 7.8Proof of conceptEPSS 10%scintilla · scintillaSep 14, 2019
- CVE-2017-880331Monitor
Notepad++ 7.3.3 (32-bit) with Hex Editor Plugin v0.9.5 might allow user-assisted attackers to execute code via a crafted file, because of a
HighCVSS 7.8No exploitEPSS 2%mh-nexus · hex editorJul 5, 2017
- CVE-2022-3216831Monitor
notepad-plus-plus - DLL Hijacking
HighCVSS 7.8No exploitEPSS 1%notepad-plus-plus · notepad\+\+Sep 28, 2022
- CVE-2026-4877831Monitor
Notepad++: Arbitrary Code Execution via config.xml commandLineInterpreter
HighCVSS 7.8Proof of conceptEPSS 1%notepad-plus-plus · notepad\+\+Jun 26, 2026
- CVE-2023-4745231Monitor
An Untrusted search path vulnerability in notepad++ 6.5 allows local users to gain escalated privileges through the msimg32.dll file in the
HighCVSS 7.8No exploitEPSS 1%notepad-plus-plus · notepad\+\+Nov 30, 2023
- CVE-2023-4003131Monitor
Notepad++ vulnerable to heap buffer write overflow in Utf8_16_Read::convert
HighCVSS 7.8Proof of conceptEPSS 1%notepad-plus-plus · notepad\+\+Aug 25, 2023
- CVE-2023-640131Monitor
NotePad++ dbghelp.exe uncontrolled search path
HighCVSS 7.8Proof of conceptEPSS 0%notepad-plus-plus · notepad\+\+Nov 30, 2023
- CVE-2026-4880031Monitor
Notepad++: Arbitrary Code Execution via shortcuts.xml UserCommand Injection
HighCVSS 7.8Proof of conceptEPSS 0%notepad-plus-plus · notepad\+\+Jun 26, 2026
- CVE-2026-5288431Monitor
Notepad++: CVE-2026-48800 Bypass
HighCVSS 7.8No exploitEPSS 0%notepad-plus-plus · notepad\+\+Jun 26, 2026
- CVE-2026-552531Monitor
Stack-Based Buffer Overflow in Notepad++ File Drop Handler leads to DoS
HighCVSS 7.8No exploitEPSS 0%notepad-plus-plus · notepad\+\+Apr 10, 2026
- CVE-2026-4671030Monitor
Notepad++: Privilege Escalation in the Installer via Uncontrolled Executable Search Path
HighCVSS 7.5No exploitEPSS 0%notepad-plus-plus · notepad\+\+Jun 26, 2026
- CVE-2026-5288530Monitor
Notepad++ TOCTOU: HMAC Checks Disk, Executes from Memory
HighCVSS 7.5Proof of conceptEPSS 0%notepad-plus-plus · notepad\+\+Jun 26, 2026
- CVE-2026-2592629Monitor
Notepad++ has an Untrusted Search Path
HighCVSS 7.3No exploitEPSS 0%notepad-plus-plus · notepad\+\+Feb 18, 2026
- CVE-2022-3190126Monitor
Buffer overflow in function Notepad_plus::addHotSpot in Notepad++ v8.4.3 and earlier allows attackers to crash the application via two craft
MediumCVSS 6.5Proof of conceptEPSS 1%notepad-plus-plus · notepad\+\+Jan 19, 2023
- CVE-2022-3190222Monitor
Notepad++ v8.4.1 was discovered to contain a stack overflow via the component Finder::add().
MediumCVSS 5.5Proof of conceptEPSS 1%notepad-plus-plus · notepad\+\+Jan 31, 2023
- CVE-2023-4016422Monitor
Notepad++ global buffer read overflow in nsCodingStateMachine::NextState
MediumCVSS 5.5No exploitEPSS 1%notepad-plus-plus · notepad\+\+Aug 25, 2023
- CVE-2023-4016622Monitor
Notepad++ heap buffer read overflow in FileManager::detectLanguageFromTextBegining
MediumCVSS 5.5No exploitEPSS 0%notepad-plus-plus · notepad\+\+Aug 25, 2023
- CVE-2023-4003622Monitor
Notepad++ global buffer read overflow in CharDistributionAnalysis::HandleOneChar
MediumCVSS 5.5No exploitEPSS 0%notepad-plus-plus · notepad\+\+Aug 25, 2023
- CVE-2026-4877020Monitor
Notepad++ WM_COPYDATA COPYDATA_FULL_CMDLINE local DoS crash
MediumCVSS 5.0Proof of conceptEPSS 0%notepad-plus-plus · notepad\+\+Jun 26, 2026
- CVE-2026-653918Monitor
Notepad++ 8.9.3 Format String Injection via nativeLang.xml
MediumCVSS 4.6No exploitEPSS 0%notepad-plus-plus · notepad\+\+Apr 30, 2026