Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

notepad-plus-plus — Vulnerabilities & Security Advisories 25

All 25 CVE vulnerabilities found in notepad-plus-plus, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities associated with Notepad++, a text editor developed by Don Ho, focusing on specific weakness types and relevant security tags. It collects reported flaws ranging from memory corruption to logic errors, covering the historical timeline of disclosures for this software. Readers can use this resource to track vendor advisories, understand the prevalence of specific weakness classes within the application, and review the product's overall vulnerability history. The data is presented to facilitate technical analysis rather than marketing, allowing security professionals and developers to identify patterns in past incidents. By examining the aggregated entries, users can assess how frequently certain types of bugs appear and evaluate the responsiveness of the development team to reported issues. This collection serves as a reference point for risk assessment, helping organizations determine if their usage of Notepad++ aligns with current security standards. The entries are organized to highlight the nature of each defect, providing context for why a particular issue was classified under its specific weakness type. This approach supports informed decision-making regarding software maintenance and patching strategies for environments where this text editor is deployed.

Vendor: notepad-plus-plus

CVE ID Title CVSS Severity Published
CVE-2026-85995 Notepad++: Authenticode verification bypass allows modified updater execution CWE-347 7.3 High 2026-09-22
CVE-2026-86056 Notepad++: Null pointer dereference in NPPM_SAVESESSION message handler causes crash (DoS) CWE-476 5.5 Medium 2026-09-22
CVE-2026-77605 Notepad++ “Run by system” executes *.txt.cmd when user selected *.txt (target confusion → command execution) CWE-20 7.8 High 2026-09-22
CVE-2026-86054 Notepad++: Stack Buffer Overflow in `NppParameters::writeSession` via overlong session path CWE-121 7.8 High 2026-09-22
CVE-2026-85288 Notepad++: Shortcuts.xml macro HMAC bypass still reachable via the "Run a Macro Multiple Times" dialog CWE-78 6.7 Medium 2026-09-22
CVE-2026-85279 Notepad++: Stack Buffer Overflow in Plugin Lexer Loading via Unchecked GetLexerCount() Return Value CWE-121 8.6 High 2026-09-22
CVE-2026-57233 Notepad++: Path Traversal (Zip Slip) in WinGup Plugin Extraction CWE-22 8.1 High 2026-08-17
CVE-2026-52886 Notepad++: session.xml backupFilePath starts_with Bypass CWE-22 5.1 Medium 2026-08-17
CVE-2026-71858 Notepad++: shortcuts.xml Macro HMAC Bypass Enables Conditional Elevated Command Execution CWE-78 5.4 Medium 2026-08-17
CVE-2026-54758 Notepad++: Stack Buffer Overflow in expandNppEnvironmentStrs CWE-121 7.8 High 2026-08-17
CVE-2026-73250 Notepad++: Install-time PowerShell command injection through installation path CWE-77 5.4 Medium 2026-08-11
CVE-2026-48770 Notepad++ WM_COPYDATA COPYDATA_FULL_CMDLINE local DoS crash CWE-125 5.0 Medium 2026-06-26
CVE-2026-48778 Notepad++: Arbitrary Code Execution via config.xml commandLineInterpreter CWE-78 7.8 High 2026-06-26
CVE-2026-52885 Notepad++ TOCTOU: HMAC Checks Disk, Executes from Memory CWE-367 - - 2026-06-26
CVE-2026-46710 Notepad++: Privilege Escalation in the Installer via Uncontrolled Executable Search Path CWE-426 - - 2026-06-26
CVE-2026-48800 Notepad++: Arbitrary Code Execution via shortcuts.xml UserCommand Injection CWE-78 7.8 High 2026-06-26
CVE-2026-52884 Notepad++: CVE-2026-48800 Bypass CWE-42 7.8 High 2026-06-26
CVE-2026-25926 Notepad++ has an Untrusted Search Path CWE-426 7.3 High 2026-02-18
CVE-2025-15556 Notepad++ < 8.8.9 WinGUp Updater Lacks Update Integrity Verification CWE-494 7.0AI High AI 2026-02-03
CVE-2025-49144 Notepad++ Privilege Escalation in Installer via Uncontrolled Executable Search Path CWE-272 7.3 High 2025-06-23
CVE-2023-40166 Notepad++ heap buffer read overflow in FileManager::detectLanguageFromTextBegining CWE-120 5.5 Medium 2023-08-25
CVE-2023-40164 Notepad++ global buffer read overflow in nsCodingStateMachine::NextState CWE-120 5.5 Medium 2023-08-25
CVE-2023-40036 Notepad++ global buffer read overflow in CharDistributionAnalysis::HandleOneChar CWE-120 5.5 Medium 2023-08-25
CVE-2023-40031 Notepad++ vulnerable to heap buffer write overflow in Utf8_16_Read::convert CWE-120 7.8 High 2023-08-25
CVE-2022-32168 notepad-plus-plus - DLL Hijacking CWE-427 7.8 - 2022-09-28

All 25 known CVE vulnerabilities affecting notepad-plus-plus with full Chinese analysis, references, and POCs where available.