CVE-2019-16294: Notepad-Plus-Plus Notepad++
High severity, CVSS 7.8. EPSS: 9.8% chance of exploitation in the next 30 days.
SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafted .ml file.
Affected products
- Notepad-Plus-Plus Notepad++: before 7.7 (fixed in 7.7)
- Scintilla Scintilla: affected versions not specified
Published 2019-09-14. Last modified 2026-06-17.