tag
Notepad++
CVE-2026-3008
binary
MEDIUM
Notepad++ nativeLang.xml Format String Crash / Info Disclosure — CVE-2026-3008
Notepad++'s Find Results panel initializer (sub1400916C0) retrieves the localized find-result-hits string from nativeLang.xml and passes it directly as the format string argument to wsprintfW, with no accompanying variadic data arguments and no validation of…
Unverified
2026-07-05
CVE-2026-48770, CVE-2026-48778, CVE-2026-48800
binary
HIGH 5
Notepad++ <= 8.9.6 Multiple Vulnerabilities (CVE-2026-48770, CVE-2026-48778, CVE-2026-48800)
This PoC set covers three Notepad++ vulnerabilities affecting versions up to 8.9.6. CVE-2026-48770 demonstrates an out-of-bounds read crash by sending malformed WMCOPYDATA data to a running Notepad++ process. CVE-2026-48778 and CVE-2026-48800 demonstrate…
Patched
2026-05-28