Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

vim — Vulnerabilities & Security Advisories 63

All 63 CVE vulnerabilities found in vim, with AI-generated Chinese analysis, references, and POCs.

This page aggregates Common Weakness Enumerations (CWEs) associated with the text editor product vim, developed by Bram Moolenaar and the open-source community. It collects reported security vulnerabilities affecting this specific software implementation, covering historical data from the initial public releases through to recent updates. By reviewing this resource, security professionals can track advisory disclosures issued by the vendor and third-party auditors, gaining insight into how specific weakness classes manifest within the codebase. Users can also look up the product’s vulnerability history to understand the evolution of security issues over time and assess the impact of patches. The content focuses on documenting flaws such as buffer overflows, integer overflows, and improper input validation that have been identified in various versions. This aggregation serves as a centralized reference for analyzing the security posture of vim, facilitating informed decisions regarding deployment and mitigation strategies. The page does not include marketing commentary or promotional material but instead presents factual data derived from recognized security databases and official announcements. Readers are encouraged to use this information to correlate specific weaknesses with version-specific details, thereby enhancing their understanding of the threat landscape surrounding this widely used command-line editor.

Vendor: unspecified

CVE IDTitleCVSSSeverityPublished
CVE-2026-55693 Vim: Out-of-bounds Write in Spell File Word Count CWE-787--2026-06-25
CVE-2026-55892 Vim: Out-of-bounds Write in Spell File Prefix Dump CWE-787 5.5 Medium2026-06-25
CVE-2026-55895 Vim: Vimscript Code Injection in netrw NetrwLocalRmFile() via crafted filename CWE-78--2026-06-25
CVE-2026-57451 Vim: Out-of-bounds Read in Text Property Count CWE-125 5.3 Medium2026-06-25
CVE-2026-57452 Vim: Out-of-bounds Read with libsodium-encrypted Files CWE-125 5.5 Medium2026-06-25
CVE-2026-57453 Vim: PowerShell Command Injection via Unescaped Filename in zip.vim Extraction CWE-77 6.5 Medium2026-06-25
CVE-2026-57454 Vim: Out-of-bounds Read with Text Properties CWE-125--2026-06-25
CVE-2026-57455 Vim: Stack out-of-bounds write in `spell_soundfold_sofo()` via an over-length `soundfold()` argument CWE-787--2026-06-25
CVE-2026-57456 Vim: Arbitrary Code Execution via Python Omni-Completion Docstrings CWE-94--2026-06-25
CVE-2026-52860 Vim: Arbitrary Code Execution via Python Omni-Completion CWE-94--2026-06-11
CVE-2026-52859 Vim: Out-of-bounds Read in Terminal Screen Snapshot CWE-125--2026-06-11
CVE-2026-52858 Vim: Arbitrary Code Execution via Python Omni-Completion CWE-94--2026-06-11
CVE-2026-47162 Vim: Vimscript Code Injection in netrw NetrwBookHistSave() via crafted directory name CWE-74--2026-06-11
CVE-2026-47167 Vim: Vimscript Code Injection in cucumber filetype plugin via crafted step-definition regex CWE-94--2026-06-11
CVE-2026-46483 Vim: Command injection in tar#Vimuntar via missing shellescape {special} flag CWE-78 3.6 Low2026-05-15
CVE-2026-45130 Vim: Heap Buffer Overflow in spell file loading CWE-122 6.6 Medium2026-05-08
CVE-2026-44656 Vim: OS Command Injection via 'path' completion CWE-78 7.8AIHighAI2026-05-08
CVE-2026-42307 Vim: OS Command Injection in netrw CWE-78 4.4 Medium2026-05-08
CVE-2026-41411 Vim: Command injection via backtick expansion in tag filenames CWE-78 6.6 Medium2026-04-24
CVE-2026-39881 Vim Ex command injection in Vims NetBeans integration CWE-94 5.0 Medium2026-04-08
CVE-2026-35177 Path traversal issue with zip.vim in Vim CWE-22 4.1 Medium2026-04-06
CVE-2026-34982 Vim modeline bypass via various options affects Vim < 9.2.0276 CWE-78 8.2 High2026-04-06
CVE-2026-34714 Vim 操作系统命令注入漏洞 CWE-78 9.2 Critical2026-03-30
CVE-2026-33412 Vim affected by Command injection via newline in glob() CWE-78 5.6 Medium2026-03-24
CVE-2026-32249 NFA regex engine NULL pointer dereference affects Vim < 9.2.0137 CWE-476 5.3 Medium2026-03-12
CVE-2026-28422 Vim has stack-buffer-overflow in build_stl_str_hl() CWE-121 2.2 Low2026-02-27
CVE-2026-28421 Vim has a heap-buffer-overflow and a segmentation fault CWE-20 5.3 Medium2026-02-27
CVE-2026-28420 Vim has Heap-based Buffer Overflow and OOB Read in :terminal CWE-122 4.4 Medium2026-02-27
CVE-2026-28419 Vim has Heap-based Buffer Underflow in Emacs tags parsing CWE-124 5.3 Medium2026-02-27
CVE-2026-28418 Vim has Heap-based Buffer Overflow in Emacs tags parsing CWE-122 4.4 Medium2026-02-27

All 63 known CVE vulnerabilities affecting vim with full Chinese analysis, references, and POCs where available.