VYPR

Notepad Plus Plus

by Notepad Plus Plus

Source repositories

CVEs (27)

  • CVE-2026-52885MedJun 26, 2026
    risk 0.00cvss 6.3epss 0.00

    Notepad++ is a free and open-source source code editor. Prior to 8.9.6.4, NppCommands.cpp checks the HMAC of the on-disk shortcuts.xml at the moment a user command fires (Time-of-Check). However, the command payload is taken from the in-memory _userCommands vector, which is…

  • CVE-2026-52884HigJun 26, 2026
    risk 0.00cvss 7.8epss 0.00

    Notepad++ is a free and open-source source code editor. In v8.9.6.1, isInTrustedDirectory() does NOT canonicalize the path before checking. It uses a prefix-based check (PathIsPrefix() or equivalent) that matches paths starting with trusted directory strings. A path traversal…

  • CVE-2026-48800HigJun 26, 2026
    risk 0.00cvss 7.8epss 0.00

    Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, the tag text content inside in shortcuts.xml is read by NppXml::value(aNode) (Parameters.cpp:3658) in the feedUserCmds() function and stored in UserCommand._cmd without any…

  • CVE-2026-48770MedJun 26, 2026
    risk 0.00cvss 5.0epss 0.00

    Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, a local process in the same interactive Windows session can send a malformed WM_COPYDATA message to Notepad++ using the COPYDATA_FULL_CMDLINE path. The handler appears to process COPYDATASTRUCT.lpData as…

  • CVE-2026-46710HigJun 26, 2026
    risk 0.00cvss 7.8epss 0.00

    Notepad++ is a free and open-source source code editor. From 8.9.4 until 8.9.6, Notepad++ contains a local privilege escalation vulnerability in the installer. During installation, the installer invokes powershell.exe without using an absolute path after setting the working…

  • CVE-2022-32168HigSep 28, 2022
    risk 0.00cvss 7.8epss 0.01

    Notepad++ versions 8.4.1 and before are vulnerable to DLL hijacking where an attacker can replace the vulnerable dll (UxTheme.dll) with his own dll and run arbitrary code in the context of Notepad++.

  • CVE-2008-3436Aug 1, 2008
    risk 0.00cvss epss 0.02

    The GUP generic update process in Notepad++ before 4.8.1 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.

Page 2 of 2