CVE-2019-16294: Notepad-Plus-Plus Notepad++

High severity, CVSS 7.8. EPSS: 9.8% chance of exploitation in the next 30 days.

SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafted .ml file.

Affected products

Published 2019-09-14. Last modified 2026-06-17.