notepad-plus-plus notepad-plus-plus是notepad-plus-plus团队的一款文本编辑软件。 notepad-plus-plus 8.9.6.1之前版本存在缓冲区错误漏洞,该漏洞源于处理WM_COPYDATA消息时未正确限制COPYDATASTRUCT.lpData数据长度,可能导致同一交互式Windows会话中的本地进程发送恶意消息,造成拒绝服务。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| notepad-plus-plus | notepad-plus-plus | < 8.9.6.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| notepad-plus-plus | notepad-plus-plus | < 8.9.6.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-52884 | 7.8 HIGH | Notepad++: CVE-2026-48800 Bypass |
| CVE-2026-48778 | 7.8 HIGH | Notepad++: Arbitrary Code Execution via config.xml commandLineInterpreter |
| CVE-2026-48800 | 7.8 HIGH | Notepad++: Arbitrary Code Execution via shortcuts.xml UserCommand Injection |
| CVE-2026-52885 | Notepad++ TOCTOU: HMAC Checks Disk, Executes from Memory | |
| CVE-2026-46710 | Notepad++: Privilege Escalation in the Installer via Uncontrolled Executable Search Path |
No comments yet