CVE-2026-73250
- EPSS 0.13%
- Veröffentlicht 11.08.2026 22:04:54
- Zuletzt bearbeitet 09.09.2026 20:58:37
Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the Notepad++ Windows 11 x64 and ARM64 installer passes the attacker-influenced installation directory `$INSTDIR` from PowerEditor/installer/nppSetup.nsi into a PowerShell `-Comm...
- EPSS 0.26%
- Veröffentlicht 26.06.2026 20:22:17
- Zuletzt bearbeitet 29.06.2026 21:21:52
Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, a local process in the same interactive Windows session can send a malformed WM_COPYDATA message to Notepad++ using the COPYDATA_FULL_CMDLINE path. The handler appears to proce...
CVE-2026-48778
- EPSS 1.31%
- Veröffentlicht 26.06.2026 20:21:17
- Zuletzt bearbeitet 29.06.2026 21:22:02
Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, the <GUIConfig name="commandLineInterpreter"> tag in config.xml is read by NppXml::value() (Parameters.cpp:6430) and stored in _nppGUI._commandLineInterpreter without any valid...
CVE-2026-52885
- EPSS 0.13%
- Veröffentlicht 26.06.2026 20:19:04
- Zuletzt bearbeitet 29.06.2026 21:22:34
Notepad++ is a free and open-source source code editor. Prior to 8.9.6.4, NppCommands.cpp checks the HMAC of the on-disk shortcuts.xml at the moment a user command fires (Time-of-Check). However, the command payload is taken from the in-memory _userC...
CVE-2026-46710
- EPSS 0.11%
- Veröffentlicht 26.06.2026 20:16:16
- Zuletzt bearbeitet 29.06.2026 21:21:38
Notepad++ is a free and open-source source code editor. From 8.9.4 until 8.9.6, Notepad++ contains a local privilege escalation vulnerability in the installer. During installation, the installer invokes powershell.exe without using an absolute path a...
CVE-2026-48800
- EPSS 0.36%
- Veröffentlicht 26.06.2026 20:12:43
- Zuletzt bearbeitet 30.06.2026 05:19:35
Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, the <Command> tag text content inside <UserDefinedCommands> in shortcuts.xml is read by NppXml::value(aNode) (Parameters.cpp:3658) in the feedUserCmds() function and stored in ...
CVE-2026-52884
- EPSS 0.21%
- Veröffentlicht 26.06.2026 20:11:40
- Zuletzt bearbeitet 29.06.2026 21:22:26
Notepad++ is a free and open-source source code editor. In v8.9.6.1, isInTrustedDirectory() does NOT canonicalize the path before checking. It uses a prefix-based check (PathIsPrefix() or equivalent) that matches paths starting with trusted directory...
CVE-2026-6539
- EPSS 0.19%
- Veröffentlicht 30.04.2026 20:31:54
- Zuletzt bearbeitet 01.05.2026 19:30:02
Notepad++ 8.9.3 contains a format string injection vulnerability in the Find Results panel handler that allows attackers to cause denial of service and information disclosure by crafting a malicious nativeLang.xml language pack file. Attackers can di...
CVE-2026-25926
- EPSS 0.25%
- Veröffentlicht 18.02.2026 23:07:36
- Zuletzt bearbeitet 19.02.2026 18:32:34
Notepad++ is a free and open-source source code editor. An Unsafe Search Path vulnerability (CWE-426) exists in versions prior to 8.9.2 when launching Windows Explorer without an absolute executable path. This may allow execution of a malicious explo...
CVE-2025-15556
- EPSS 1.27%
- Veröffentlicht 03.02.2026 01:15:57
- Zuletzt bearbeitet 13.02.2026 14:03:47
Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability where downloaded update metadata and installers are not cryptographically verified. An attacker able to intercept or redirect upd...