Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

vim — Vulnerabilities & Security Advisories 76

All 76 CVE vulnerabilities found in vim, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability records for the vim text editor, specifically documenting known weaknesses such as buffer overflows, denial-of-service triggers, and path traversal issues within the open-source codebase. It collects critical security flaws reported across multiple releases, covering a multi-year span of advisory history. Visitors can track vendor-specific advisories, analyze the evolution of a particular weakness class, and review the complete vulnerability history associated with the product.

Vendor: unspecified

CVE ID Title CVSS Severity Published
CVE-2026-43961 Vim: vimscript injection via unescaped filename in netrw s:netrwmarkfile() filter() expression allows arbitrary code execution CWE-94 7.8 High 2026-08-19
CVE-2026-73073 Vim: Arbitrary Ex Command Execution in C Omni-Completion CWE-94 7.1 High 2026-08-18
CVE-2026-73078 Vim: Arbitrary Code Execution via Netrw Menu Construction CWE-77 8.6 High 2026-08-11
CVE-2026-73077 Vim: Arbitrary Code Execution via Shell Keyword Lookup CWE-78 8.4 High 2026-08-11
CVE-2026-73076 Vim: Arbitrary Command Execution via Malicious `.VimballRecord` Entry Replay in `vimball.vim` CWE-94 8.4 High 2026-08-11
CVE-2026-73075 Vim: Out-of-bounds Access in Popup Opacity Handling CWE-124 4.6 Medium 2026-08-11
CVE-2026-73074 Vim: Heap Buffer Overflow in Text Property Handling CWE-190 7.1 High 2026-08-11
CVE-2026-73072 Vim: Heap Buffer Overflow when Loading a Spell File CWE-122 8.5 High 2026-08-11
CVE-2026-73071 Vim: Use-after-free in JSON Decoding CWE-416 3.3 Low 2026-08-11
CVE-2026-73070 Vim: Stack Buffer Overflow in the Vim Socket Server CWE-121 6.8 Medium 2026-08-11
CVE-2026-59856 Vim: Arbitrary Code Execution via PHP Omni-Completion CWE-94 - - 2026-07-09
CVE-2026-59858 Vim: Arbitrary Code Execution via C Omni-Completion CWE-94 - - 2026-07-09
CVE-2026-59857 Vim: Out-of-bounds Write in SAL Soundfolding CWE-787 - - 2026-07-09
CVE-2026-55693 Vim: Out-of-bounds Write in Spell File Word Count CWE-787 - - 2026-06-25
CVE-2026-55892 Vim: Out-of-bounds Write in Spell File Prefix Dump CWE-787 5.5 Medium 2026-06-25
CVE-2026-55895 Vim: Vimscript Code Injection in netrw NetrwLocalRmFile() via crafted filename CWE-78 - - 2026-06-25
CVE-2026-57451 Vim: Out-of-bounds Read in Text Property Count CWE-125 5.3 Medium 2026-06-25
CVE-2026-57452 Vim: Out-of-bounds Read with libsodium-encrypted Files CWE-125 5.5 Medium 2026-06-25
CVE-2026-57453 Vim: PowerShell Command Injection via Unescaped Filename in zip.vim Extraction CWE-77 6.5 Medium 2026-06-25
CVE-2026-57454 Vim: Out-of-bounds Read with Text Properties CWE-125 - - 2026-06-25
CVE-2026-57455 Vim: Stack out-of-bounds write in `spell_soundfold_sofo()` via an over-length `soundfold()` argument CWE-787 - - 2026-06-25
CVE-2026-57456 Vim: Arbitrary Code Execution via Python Omni-Completion Docstrings CWE-94 - - 2026-06-25
CVE-2026-52860 Vim: Arbitrary Code Execution via Python Omni-Completion CWE-94 7.5 High 2026-06-11
CVE-2026-52859 Vim: Out-of-bounds Read in Terminal Screen Snapshot CWE-125 - - 2026-06-11
CVE-2026-52858 Vim: Arbitrary Code Execution via Python Omni-Completion CWE-94 - - 2026-06-11
CVE-2026-47162 Vim: Vimscript Code Injection in netrw NetrwBookHistSave() via crafted directory name CWE-74 7.3 High 2026-06-11
CVE-2026-47167 Vim: Vimscript Code Injection in cucumber filetype plugin via crafted step-definition regex CWE-94 - - 2026-06-11
CVE-2026-46483 Vim: Command injection in tar#Vimuntar via missing shellescape {special} flag CWE-78 3.6 Low 2026-05-15
CVE-2026-45130 Vim: Heap Buffer Overflow in spell file loading CWE-122 6.6 Medium 2026-05-08
CVE-2026-44656 Vim: OS Command Injection via 'path' completion CWE-78 7.8AI High AI 2026-05-08

All 76 known CVE vulnerabilities affecting vim with full Chinese analysis, references, and POCs where available.