PoC Archive PoC Archive

tag

Notepad++

  • CVE-2026-3008 binary MEDIUM

    Notepad++ nativeLang.xml Format String Crash / Info Disclosure — CVE-2026-3008

    Notepad++'s Find Results panel initializer (sub1400916C0) retrieves the localized find-result-hits string from nativeLang.xml and passes it directly as the format string argument to wsprintfW, with no accompanying variadic data arguments and no validation of…

    Unverified 2026-07-05
  • CVE-2026-48770, CVE-2026-48778, CVE-2026-48800 binary HIGH 5

    Notepad++ <= 8.9.6 Multiple Vulnerabilities (CVE-2026-48770, CVE-2026-48778, CVE-2026-48800)

    This PoC set covers three Notepad++ vulnerabilities affecting versions up to 8.9.6. CVE-2026-48770 demonstrates an out-of-bounds read crash by sending malformed WMCOPYDATA data to a running Notepad++ process. CVE-2026-48778 and CVE-2026-48800 demonstrate…

    Patched 2026-05-28