Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

notepad-plus-plus — Vulnerabilities & Security Advisories 25

Browse all 25 CVE security advisories affecting notepad-plus-plus. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Notepad-plus-plus serves as a lightweight text editor and source code viewer for Windows, supporting multiple programming languages. Historically, it has been susceptible to remote code execution, buffer overflow, and privilege escalation vulnerabilities, often through crafted file handling. The application has faced eight CVEs, including issues allowing arbitrary code execution via malicious files or insecure DLL loading. While no major security incidents have been widely documented, its frequent updates suggest ongoing attention to vulnerabilities. Users should exercise caution with untrusted files due to potential RCE risks, though the application remains a popular choice for developers seeking a free, feature-rich editing tool.

Top products by notepad-plus-plus: notepad-plus-plus
CVE ID Title CVSS Severity Published
CVE-2026-85995 Notepad++: Authenticode verification bypass allows modified updater execution — notepad-plus-plus CWE-347 7.3 High 2026-09-22
CVE-2026-86056 Notepad++: Null pointer dereference in NPPM_SAVESESSION message handler causes crash (DoS) — notepad-plus-plus CWE-476 5.5 Medium 2026-09-22
CVE-2026-77605 Notepad++ “Run by system” executes *.txt.cmd when user selected *.txt (target confusion → command execution) — notepad-plus-plus CWE-20 7.8 High 2026-09-22
CVE-2026-86054 Notepad++: Stack Buffer Overflow in `NppParameters::writeSession` via overlong session path — notepad-plus-plus CWE-121 7.8 High 2026-09-22
CVE-2026-85288 Notepad++: Shortcuts.xml macro HMAC bypass still reachable via the "Run a Macro Multiple Times" dialog — notepad-plus-plus CWE-78 6.7 Medium 2026-09-22
CVE-2026-85279 Notepad++: Stack Buffer Overflow in Plugin Lexer Loading via Unchecked GetLexerCount() Return Value — notepad-plus-plus CWE-121 8.6 High 2026-09-22
CVE-2026-57233 Notepad++: Path Traversal (Zip Slip) in WinGup Plugin Extraction — notepad-plus-plus CWE-22 8.1 High 2026-08-17
CVE-2026-52886 Notepad++: session.xml backupFilePath starts_with Bypass — notepad-plus-plus CWE-22 5.1 Medium 2026-08-17
CVE-2026-71858 Notepad++: shortcuts.xml Macro HMAC Bypass Enables Conditional Elevated Command Execution — notepad-plus-plus CWE-78 5.4 Medium 2026-08-17
CVE-2026-54758 Notepad++: Stack Buffer Overflow in expandNppEnvironmentStrs — notepad-plus-plus CWE-121 7.8 High 2026-08-17
CVE-2026-73250 Notepad++: Install-time PowerShell command injection through installation path — notepad-plus-plus CWE-77 5.4 Medium 2026-08-11
CVE-2026-48770 Notepad++ WM_COPYDATA COPYDATA_FULL_CMDLINE local DoS crash — notepad-plus-plus CWE-125 5.0 Medium 2026-06-26
CVE-2026-48778 Notepad++: Arbitrary Code Execution via config.xml commandLineInterpreter — notepad-plus-plus CWE-78 7.8 High 2026-06-26
CVE-2026-52885 Notepad++ TOCTOU: HMAC Checks Disk, Executes from Memory — notepad-plus-plus CWE-367 - - 2026-06-26
CVE-2026-46710 Notepad++: Privilege Escalation in the Installer via Uncontrolled Executable Search Path — notepad-plus-plus CWE-426 - - 2026-06-26
CVE-2026-48800 Notepad++: Arbitrary Code Execution via shortcuts.xml UserCommand Injection — notepad-plus-plus CWE-78 7.8 High 2026-06-26
CVE-2026-52884 Notepad++: CVE-2026-48800 Bypass — notepad-plus-plus CWE-42 7.8 High 2026-06-26
CVE-2026-25926 Notepad++ has an Untrusted Search Path — notepad-plus-plus CWE-426 7.3 High 2026-02-18
CVE-2025-15556 Notepad++ < 8.8.9 WinGUp Updater Lacks Update Integrity Verification — notepad-plus-plus CWE-494 7.0AI High AI 2026-02-03
CVE-2025-49144 Notepad++ Privilege Escalation in Installer via Uncontrolled Executable Search Path — notepad-plus-plus CWE-272 7.3 High 2025-06-23
CVE-2023-40166 Notepad++ heap buffer read overflow in FileManager::detectLanguageFromTextBegining — notepad-plus-plus CWE-120 5.5 Medium 2023-08-25
CVE-2023-40164 Notepad++ global buffer read overflow in nsCodingStateMachine::NextState — notepad-plus-plus CWE-120 5.5 Medium 2023-08-25
CVE-2023-40036 Notepad++ global buffer read overflow in CharDistributionAnalysis::HandleOneChar — notepad-plus-plus CWE-120 5.5 Medium 2023-08-25
CVE-2023-40031 Notepad++ vulnerable to heap buffer write overflow in Utf8_16_Read::convert — notepad-plus-plus CWE-120 7.8 High 2023-08-25
CVE-2022-32168 notepad-plus-plus - DLL Hijacking — notepad-plus-plus CWE-427 7.8 - 2022-09-28

This page lists every published CVE security advisory associated with notepad-plus-plus. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.