notepad-plus-plus notepad-plus-plus是notepad-plus-plus团队的一款文本编辑软件。 notepad-plus-plus 8.9.4版本至8.9.6之前版本存在权限许可和访问控制问题漏洞,该漏洞源于安装过程中未使用绝对路径调用powershell.exe,可能导致攻击者在用户可写的自定义安装目录中预先放置恶意powershell.exe,在特权用户运行安装程序并选择该目录时,以安装程序提升权限启动恶意程序。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| notepad-plus-plus | notepad-plus-plus | >= 8.9.4, < 8.9.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| notepad-plus-plus | notepad-plus-plus | >= 8.9.4, < 8.9.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-52884 | 7.8 HIGH | Notepad++: CVE-2026-48800 Bypass |
| CVE-2026-48778 | 7.8 HIGH | Notepad++: Arbitrary Code Execution via config.xml commandLineInterpreter |
| CVE-2026-48800 | 7.8 HIGH | Notepad++: Arbitrary Code Execution via shortcuts.xml UserCommand Injection |
| CVE-2026-48770 | 5.0 MEDIUM | Notepad++ WM_COPYDATA COPYDATA_FULL_CMDLINE local DoS crash |
| CVE-2026-52885 | Notepad++ TOCTOU: HMAC Checks Disk, Executes from Memory |
No comments yet