notepad-plus-plus notepad-plus-plus是notepad-plus-plus团队的一款文本编辑软件。 notepad-plus-plus 8.9.6.4之前版本存在竞争条件问题漏洞,该漏洞源于NppCommands.cpp中的检查时间与使用时间(TOCTOU)问题,可能导致具有shortcuts.xml写入权限的攻击者在启动前放置恶意版本并在加载后恢复合法文件,从而导致恶意载荷从内存中执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| notepad-plus-plus | notepad-plus-plus | < 8.9.6.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| notepad-plus-plus | notepad-plus-plus | < 8.9.6.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-52884 | 7.8 HIGH | Notepad++: CVE-2026-48800 Bypass |
| CVE-2026-48778 | 7.8 HIGH | Notepad++: Arbitrary Code Execution via config.xml commandLineInterpreter |
| CVE-2026-48800 | 7.8 HIGH | Notepad++: Arbitrary Code Execution via shortcuts.xml UserCommand Injection |
| CVE-2026-48770 | 5.0 MEDIUM | Notepad++ WM_COPYDATA COPYDATA_FULL_CMDLINE local DoS crash |
| CVE-2026-46710 | Notepad++: Privilege Escalation in the Installer via Uncontrolled Executable Search Path |
No comments yet