Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

notepad-plus-plus — Vulnerabilities & Security Advisories 19

All 19 CVE vulnerabilities found in notepad-plus-plus, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumerations associated with Notepad++ developed by Don Ho. It aggregates security vulnerabilities categorized by their underlying technical causes, providing a structured view of flaws impacting this popular text editor. The collection includes reported issues spanning from the product’s early releases through recent versions, covering a broad historical timeline of security incidents. Here, users can track vendor advisories issued by the Notepad++ team, understand the nature and classification of specific weakness classes affecting the software, and look up the complete vulnerability history for Notepad++. This resource is designed to help developers, security analysts, and end-users assess the risk profile of the application over time. By centralizing these records, the page offers a clear perspective on how frequently certain types of vulnerabilities have occurred and how they have been remediated. It serves as a reference for evaluating the stability and security posture of Notepad++ without requiring external research. The information presented is strictly factual, focusing on the technical details of each entry to support informed decision-making regarding updates and mitigation strategies.

Vendor: notepad-plus-plus

CVE ID Title CVSS Severity Published
CVE-2026-57233 Notepad++: Path Traversal (Zip Slip) in WinGup Plugin Extraction CWE-22 8.1 High 2026-08-17
CVE-2026-52886 Notepad++: session.xml backupFilePath starts_with Bypass CWE-22 5.1 Medium 2026-08-17
CVE-2026-71858 Notepad++: shortcuts.xml Macro HMAC Bypass Enables Conditional Elevated Command Execution CWE-78 5.4 Medium 2026-08-17
CVE-2026-54758 Notepad++: Stack Buffer Overflow in expandNppEnvironmentStrs CWE-121 7.8 High 2026-08-17
CVE-2026-73250 Notepad++: Install-time PowerShell command injection through installation path CWE-77 5.4 Medium 2026-08-11
CVE-2026-48770 Notepad++ WM_COPYDATA COPYDATA_FULL_CMDLINE local DoS crash CWE-125 5.0 Medium 2026-06-26
CVE-2026-48778 Notepad++: Arbitrary Code Execution via config.xml commandLineInterpreter CWE-78 7.8 High 2026-06-26
CVE-2026-52885 Notepad++ TOCTOU: HMAC Checks Disk, Executes from Memory CWE-367 - - 2026-06-26
CVE-2026-46710 Notepad++: Privilege Escalation in the Installer via Uncontrolled Executable Search Path CWE-426 - - 2026-06-26
CVE-2026-48800 Notepad++: Arbitrary Code Execution via shortcuts.xml UserCommand Injection CWE-78 7.8 High 2026-06-26
CVE-2026-52884 Notepad++: CVE-2026-48800 Bypass CWE-42 7.8 High 2026-06-26
CVE-2026-25926 Notepad++ has an Untrusted Search Path CWE-426 7.3 High 2026-02-18
CVE-2025-15556 Notepad++ < 8.8.9 WinGUp Updater Lacks Update Integrity Verification CWE-494 7.0AI High AI 2026-02-03
CVE-2025-49144 Notepad++ Privilege Escalation in Installer via Uncontrolled Executable Search Path CWE-272 7.3 High 2025-06-23
CVE-2023-40166 Notepad++ heap buffer read overflow in FileManager::detectLanguageFromTextBegining CWE-120 5.5 Medium 2023-08-25
CVE-2023-40164 Notepad++ global buffer read overflow in nsCodingStateMachine::NextState CWE-120 5.5 Medium 2023-08-25
CVE-2023-40036 Notepad++ global buffer read overflow in CharDistributionAnalysis::HandleOneChar CWE-120 5.5 Medium 2023-08-25
CVE-2023-40031 Notepad++ vulnerable to heap buffer write overflow in Utf8_16_Read::convert CWE-120 7.8 High 2023-08-25
CVE-2022-32168 notepad-plus-plus - DLL Hijacking CWE-427 7.8 - 2022-09-28

All 19 known CVE vulnerabilities affecting notepad-plus-plus with full Chinese analysis, references, and POCs where available.