VYPR

Bbedit

by Barebones

CVEs (3)

  • CVE-2026-82605MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading to version 16.0 is sufficient to fix…

  • CVE-2026-82604MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language Module. This manipulation causes uncontrolled recursion. Remote exploitation of the attack is possible. Upgrading to version 16.0 is recommended to address this…

  • CVE-2013-3667Dec 31, 2013
    risk 0.00cvss —epss 0.02

    The software update mechanism as used in Bare Bones Software Yojimbo before 4.0, TextWrangler before 4.5.3, and BBEdit before 10.5.5 does not properly download and verify updates before installation, which allows attackers to perform "tampering or corruption" of the updates.