CVE-2018-18447: Dotpdn Paint.net

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 2 of 2).

Affected products

  • Dotpdn Paint.net: before 4.1.2 (fixed in 4.1.2)

Published 2022-10-12. Last modified 2026-06-17.