Vulnerabilities in notepad-plus-plus
25 resultsVexday analysis
Notepad++ apresenta 14 vulnerabilidades catalogadas, com 1 sob exploração ativa e 6 divulgadas nos últimos 90 dias, indicando ritmo recente de descobertas. A ausência de críticas (CVSS alto) e a dominância de CWE-120 (buffer overflow) sugerem risco moderado, concentrado em falhas de validação de entrada que exigem monitoramento contínuo.
CVE-2025-15556HIGHNotepad++ < 8.8.9 WinGUp Updater Lacks Update Integrity VerificationEPSS 1.7%KEVCVE-2022-32168HIGHnotepad-plus-plus - DLL HijackingEPSS 0.8%CVE-2025-49144HIGHNotepad++ Privilege Escalation in Installer via Uncontrolled Executable Search PathEPSS 0.7%CVE-2026-48778HIGHNotepad++: Arbitrary Code Execution via config.xml commandLineInterpreterEPSS 0.6%CVE-2023-40031HIGHNotepad++ vulnerable to heap buffer write overflow in Utf8_16_Read::convertEPSS 0.5%CVE-2026-57233HIGHNotepad++: Path Traversal (Zip Slip) in WinGup Plugin ExtractionEPSS 0.5%CVE-2023-40164MEDIUMNotepad++ global buffer read overflow in nsCodingStateMachine::NextStateEPSS 0.5%CVE-2023-40166MEDIUMNotepad++ heap buffer read overflow in FileManager::detectLanguageFromTextBegining EPSS 0.4%CVE-2023-40036MEDIUMNotepad++ global buffer read overflow in CharDistributionAnalysis::HandleOneCharEPSS 0.4%CVE-2026-85279HIGHNotepad++: Stack Buffer Overflow in Plugin Lexer Loading via Unchecked GetLexerCount() Return ValueEPSS 0.2%CVE-2026-48800HIGHNotepad++: Arbitrary Code Execution via shortcuts.xml UserCommand InjectionEPSS 0.2%CVE-2026-52884HIGHNotepad++: CVE-2026-48800 BypassEPSS 0.2%CVE-2026-25926HIGHNotepad++ has an Untrusted Search PathEPSS 0.2%CVE-2026-86054HIGHNotepad++: Stack Buffer Overflow in `NppParameters::writeSession` via overlong session pathEPSS 0.2%CVE-2026-54758HIGHNotepad++: Stack Buffer Overflow in expandNppEnvironmentStrsEPSS 0.2%CVE-2026-73250MEDIUMNotepad++: Install-time PowerShell command injection through installation pathEPSS 0.2%CVE-2026-77605HIGHNotepad++ “Run by system” executes *.txt.cmd when user selected *.txt (target confusion → command execution)EPSS 0.2%CVE-2026-52886MEDIUMNotepad++: session.xml backupFilePath starts_with BypassEPSS 0.2%CVE-2026-86056MEDIUMNotepad++: Null pointer dereference in NPPM_SAVESESSION message handler causes crash (DoS)EPSS 0.2%CVE-2026-46710HIGHNotepad++: Privilege Escalation in the Installer via Uncontrolled Executable Search PathEPSS 0.2%