6.6
CVE-2026-3008
- EPSS 0.22%
- Veröffentlicht 27.04.2026 06:04:22
- Zuletzt bearbeitet 27.04.2026 18:57:20
- Quelle 5f57b9bf-260d-4433-bf07-b6a79e
- CVE-Watchlists
- Unerledigt
Vulnerability in Notepad++
Successful exploitation of the string injection vulnerability could allow an attacker to obtain memory address information or crash the application.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerNotepad++
≫
Produkt
Notepad++
Default Statusunaffected
Version
8.9.3
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.127 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 5f57b9bf-260d-4433-bf07-b6a79e9bb7d4 | 6.6 | 1.8 | 4.7 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
|
CWE-134 Use of Externally-Controlled Format String
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-044/
https://community.notepad-plus-plus.org/topic/27500/notepad-v8-9-4-release-candidate
https://github.com/llgsjsm/cve-2026-3008
https://llgsjsm.github.io/cve-2026-3008/
https://github.com/notepad-plus-plus/notepad-plus-plus/issues/17960