Notepad
1 CVEs tracked since 2008. Since Aug 2008, none of them reached CISA KEV.
Notepad CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2008-08 | 1 | 0 |
Products
The products that kept showing up in Notepad's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 4 most recently published vulnerabilities affecting Notepad.
- CVE-2026-6539Notepad++ 8.9.3 Format String Injection via nativeLang.xml4.4
- CVE-2026-3008Vulnerability in Notepad++6.6
- CVE-2008-3436The GUP generic update process in Notepad++ before 4.8.1 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse ...7.5
- CVE-2007-2666Stack-based buffer overflow in LexRuby.cxx (SciLexer.dll) in Scintilla 1.73, as used by notepad++ 4.1.1 and earlier, allows user-assisted remote attackers to execute arbitrary code via certain Ruby...7.6
The record
- Peak rank
- #163 in Aug 2008
- Busiest month shown
- Aug 2008, 1 CVEs
- Months with a KEV entry
- 0 since Aug 2008
- Monthly snapshots
- 1 since 2008