Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

vim — Vulnerabilities & Security Advisories 231

Browse all 231 CVE security advisories affecting vim. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Vim is a widely used, open-source text editor primarily designed for efficient code editing and system administration tasks across Unix-like operating systems. Despite its utility, the software has accumulated approximately 200 Common Vulnerabilities and Exposures (CVEs), reflecting its complex codebase and long history. Historically, these security flaws have predominantly involved remote code execution (RCE) and buffer overflow vulnerabilities, often triggered by malformed files or specific command-line arguments. While cross-site scripting is irrelevant to its terminal-based nature, privilege escalation risks have occasionally arisen through improper file permission handling or setuid configurations. Notable incidents include critical RCE flaws in the ex command interpreter and memory corruption issues within the clipboard handling subsystem. These vulnerabilities underscore the importance of keeping the editor updated, as attackers frequently exploit parsing errors to gain unauthorized system access or execute arbitrary code within the user’s environment.

Top products by vim: vim/vim vim
CVE ID Title CVSS Severity Published
CVE-2026-43961 Vim: vimscript injection via unescaped filename in netrw s:netrwmarkfile() filter() expression allows arbitrary code execution — vim CWE-94 7.8 High 2026-08-19
CVE-2026-73073 Vim: Arbitrary Ex Command Execution in C Omni-Completion — vim CWE-94 7.1 High 2026-08-18
CVE-2026-73078 Vim: Arbitrary Code Execution via Netrw Menu Construction — vim CWE-77 8.6 High 2026-08-11
CVE-2026-73077 Vim: Arbitrary Code Execution via Shell Keyword Lookup — vim CWE-78 8.4 High 2026-08-11
CVE-2026-73076 Vim: Arbitrary Command Execution via Malicious `.VimballRecord` Entry Replay in `vimball.vim` — vim CWE-94 8.4 High 2026-08-11
CVE-2026-73075 Vim: Out-of-bounds Access in Popup Opacity Handling — vim CWE-124 4.6 Medium 2026-08-11
CVE-2026-73074 Vim: Heap Buffer Overflow in Text Property Handling — vim CWE-190 7.1 High 2026-08-11
CVE-2026-73072 Vim: Heap Buffer Overflow when Loading a Spell File — vim CWE-122 8.5 High 2026-08-11
CVE-2026-73071 Vim: Use-after-free in JSON Decoding — vim CWE-416 3.3 Low 2026-08-11
CVE-2026-73070 Vim: Stack Buffer Overflow in the Vim Socket Server — vim CWE-121 6.8 Medium 2026-08-11
CVE-2026-59856 Vim: Arbitrary Code Execution via PHP Omni-Completion — vim CWE-94 - - 2026-07-09
CVE-2026-59858 Vim: Arbitrary Code Execution via C Omni-Completion — vim CWE-94 - - 2026-07-09
CVE-2026-59857 Vim: Out-of-bounds Write in SAL Soundfolding — vim CWE-787 - - 2026-07-09
CVE-2026-55693 Vim: Out-of-bounds Write in Spell File Word Count — vim CWE-787 - - 2026-06-25
CVE-2026-55892 Vim: Out-of-bounds Write in Spell File Prefix Dump — vim CWE-787 5.5 Medium 2026-06-25
CVE-2026-55895 Vim: Vimscript Code Injection in netrw NetrwLocalRmFile() via crafted filename — vim CWE-78 - - 2026-06-25
CVE-2026-57451 Vim: Out-of-bounds Read in Text Property Count — vim CWE-125 5.3 Medium 2026-06-25
CVE-2026-57452 Vim: Out-of-bounds Read with libsodium-encrypted Files — vim CWE-125 5.5 Medium 2026-06-25
CVE-2026-57453 Vim: PowerShell Command Injection via Unescaped Filename in zip.vim Extraction — vim CWE-77 6.5 Medium 2026-06-25
CVE-2026-57454 Vim: Out-of-bounds Read with Text Properties — vim CWE-125 - - 2026-06-25
CVE-2026-57455 Vim: Stack out-of-bounds write in `spell_soundfold_sofo()` via an over-length `soundfold()` argument — vim CWE-787 - - 2026-06-25
CVE-2026-57456 Vim: Arbitrary Code Execution via Python Omni-Completion Docstrings — vim CWE-94 - - 2026-06-25
CVE-2026-52860 Vim: Arbitrary Code Execution via Python Omni-Completion — vim CWE-94 7.5 High 2026-06-11
CVE-2026-52859 Vim: Out-of-bounds Read in Terminal Screen Snapshot — vim CWE-125 - - 2026-06-11
CVE-2026-52858 Vim: Arbitrary Code Execution via Python Omni-Completion — vim CWE-94 - - 2026-06-11
CVE-2026-47162 Vim: Vimscript Code Injection in netrw NetrwBookHistSave() via crafted directory name — vim CWE-74 7.3 High 2026-06-11
CVE-2026-47167 Vim: Vimscript Code Injection in cucumber filetype plugin via crafted step-definition regex — vim CWE-94 - - 2026-06-11
CVE-2026-46483 Vim: Command injection in tar#Vimuntar via missing shellescape {special} flag — vim CWE-78 3.6 Low 2026-05-15
CVE-2026-45130 Vim: Heap Buffer Overflow in spell file loading — vim CWE-122 6.6 Medium 2026-05-08
CVE-2026-44656 Vim: OS Command Injection via 'path' completion — vim CWE-78 7.8AI High AI 2026-05-08

This page lists every published CVE security advisory associated with vim. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.