Notepad-plus-plus

Notepad++

22 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.1%
  • Veröffentlicht 17.08.2026 20:16:46
  • Zuletzt bearbeitet 17.08.2026 21:16:48

Notepad++ is a free and open-source source code editor. Prior to 8.9.7, macros loaded from an attacker-controlled shortcuts.xml bypass the HMAC validation applied to UserDefinedCommands and can invoke Scintilla actions and the internal Open in Defaul...

  • EPSS 0.48%
  • Veröffentlicht 17.08.2026 20:16:44
  • Zuletzt bearbeitet 18.08.2026 19:16:58

Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the WinGup decompress function joins untrusted ZIP entry names to unzipDestTo without canonical containment validation, allowing an entry such as ../mimeTools/mimeTools.dll to ov...

  • EPSS 0.19%
  • Veröffentlicht 17.08.2026 20:16:44
  • Zuletzt bearbeitet 17.08.2026 22:17:14

Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the expandNppEnvironmentStrs function in PowerEditor/src/WinControls/StaticDialog/RunDlg/RunDlg.cpp copies a Notepad++ variable name between $( and ) into the fixed-size wchar_t ...

  • EPSS 0.18%
  • Veröffentlicht 17.08.2026 20:16:44
  • Zuletzt bearbeitet 18.08.2026 16:17:42

Notepad++ is a free and open-source source code editor. Prior to 8.9.7, Notepad++ validates the backupFilePath attribute from session.xml with std::wstring::starts_with against the expected backup directory without path normalization, allowing parent...

  • EPSS 0.13%
  • Veröffentlicht 11.08.2026 22:04:54
  • Zuletzt bearbeitet 13.08.2026 16:19:03

Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the Notepad++ Windows 11 x64 and ARM64 installer passes the attacker-influenced installation directory `$INSTDIR` from PowerEditor/installer/nppSetup.nsi into a PowerShell `-Comm...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 26.06.2026 20:22:17
  • Zuletzt bearbeitet 29.06.2026 21:21:52

Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, a local process in the same interactive Windows session can send a malformed WM_COPYDATA message to Notepad++ using the COPYDATA_FULL_CMDLINE path. The handler appears to proce...

Exploit
  • EPSS 1.31%
  • Veröffentlicht 26.06.2026 20:21:17
  • Zuletzt bearbeitet 29.06.2026 21:22:02

Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, the <GUIConfig name="commandLineInterpreter"> tag in config.xml is read by NppXml::value() (Parameters.cpp:6430) and stored in _nppGUI._commandLineInterpreter without any valid...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 26.06.2026 20:19:04
  • Zuletzt bearbeitet 29.06.2026 21:22:34

Notepad++ is a free and open-source source code editor. Prior to 8.9.6.4, NppCommands.cpp checks the HMAC of the on-disk shortcuts.xml at the moment a user command fires (Time-of-Check). However, the command payload is taken from the in-memory _userC...

  • EPSS 0.11%
  • Veröffentlicht 26.06.2026 20:16:16
  • Zuletzt bearbeitet 29.06.2026 21:21:38

Notepad++ is a free and open-source source code editor. From 8.9.4 until 8.9.6, Notepad++ contains a local privilege escalation vulnerability in the installer. During installation, the installer invokes powershell.exe without using an absolute path a...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 26.06.2026 20:12:43
  • Zuletzt bearbeitet 30.06.2026 05:19:35

Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, the <Command> tag text content inside <UserDefinedCommands> in shortcuts.xml is read by NppXml::value(aNode) (Parameters.cpp:3658) in the feedUserCmds() function and stored in ...