VulnSea

notepad-plus-plus has 6 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 6. The median CVSS is 7.5 (high). None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
6 prev 0

Products

  • notepad-plus-plus 6
6
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

notepad-plus-plus vulnerabilities

CVEs affecting notepad-plus-plus, newest first. Open any entry for full detail, references, and exploit status.

6 CVEsRSS

CVE-2026-85279High· 8.6PoC
today

Notepad++ is a free and open-source source code editor

Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ contains a stack buffer overflow in PluginsManager::loadPluginFromPath in PowerEditor/src/MISC/PluginsManager/PluginsManager.cpp because the plugin-supplie…

Midnightnotepad-plus-plus · notepad-plus-plusvia NVD
CVE-2026-85288Medium· 6.7
today

Notepad++ is a free and open-source source code editor

Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ incompletely enforces shortcuts.xml HMAC validation because WM_MACRODLGRUNMACRO, the Run a Macro Multiple Times entry point, calls macroPlayback() without …

Sunlitnotepad-plus-plus · notepad-plus-plusvia NVD
CVE-2026-77605High· 7.8
today

Notepad++ is a free and open-source source code editor

Notepad++ is a free and open-source source code editor. Prior to 8.9.8, the Folder as Workspace Run by system action in Notepad++ can resolve a different sibling file than the file selected by the user. When an attacker places a command …

Twilightnotepad-plus-plus · notepad-plus-plusvia NVD
CVE-2026-86054High· 7.8
today

Notepad++ is a free and open-source source code editor

Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ contains a stack buffer overflow in NppParameters::writeSession in PowerEditor/src/Parameters.cpp because it copies a session path derived from -settingsDi…

Twilightnotepad-plus-plus · notepad-plus-plusvia NVD
CVE-2026-86056Medium· 5.5PoC
today

Notepad++ is a free and open-source source code editor

Notepad++ is a free and open-source source code editor. Prior to 8.9.8, the NPPM_SAVESESSION handler in PowerEditor/src/NppBigSwitch.cpp converts lParam to a sessionInfo pointer and dereferences its nbFile, files, and sessionFilePathName…

Twilightnotepad-plus-plus · notepad-plus-plusvia NVD
CVE-2026-85995High· 7.3
today

Notepad++ is a free and open-source source code editor

Notepad++ is a free and open-source source code editor. From 8.9.7 until 8.9.8, the Notepad++ updater and signature verification path can accept a modified GUP.exe file whose embedded certificate metadata remains present even though its …

Twilightnotepad-plus-plus · notepad-plus-plusvia NVD
notepad-plus-plus vulnerabilities (CVEs) · VulnSea