Known Vulnerabilities for products from Vim

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Vim".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-39881 json Vim is an open source, command line text editor. Prior to 9.2.0316, a command injection vulnerability in Vim's netbeans inter... Not Provided 2026-04-08 2026-04-22
CVE-2026-35177 json Vim is an open source, command line text editor. Prior to 9.2.0280, a path traversal bypass in Vim's zip.vim plugin allows ov... Not Provided 2026-04-06 2026-04-20
CVE-2026-34982 json Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary... Not Provided 2026-04-06 2026-04-22
CVE-2026-34714 json Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, ... Not Provided 2026-03-30 2026-04-03
CVE-2025-53906 json Vim is an open source, command line text editor. Prior to version 9.1.1551, a path traversal issue in Vim’s zip.vim plugin ... Not Provided 2025-07-15 2026-04-01
CVE-2023-48706 json 4.7 - MEDIUM 2023-11-22 2024-01-05
CVE-2023-48237 json 4.3 - MEDIUM 2023-11-16 2024-01-25
CVE-2023-48236 json 4.3 - MEDIUM 2023-11-16 2024-01-25
CVE-2023-48235 json 4.3 - MEDIUM 2023-11-16 2024-01-25
CVE-2023-48234 json 4.3 - MEDIUM 2023-11-16 2024-01-25
CVE-2023-48233 json 4.3 - MEDIUM 2023-11-16 2024-01-25
CVE-2023-48232 json 4.3 - MEDIUM 2023-11-16 2024-01-25
CVE-2023-46246 json Vim is an improved version of the good old UNIX editor Vi. Heap-use-after-free in memory allocated in the function `ga_grow_i... 5.5 - MEDIUM 2023-10-27 2023-11-07
CVE-2023-5535 json Use After Free in GitHub repository vim/vim prior to v9.0.2010. 7.8 - HIGH 2023-10-11 2023-11-15
CVE-2023-5441 json NULL Pointer Dereference in GitHub repository vim/vim prior to 20d161ace307e28690229b68584f2d84556f8960. 5.5 - MEDIUM 2023-10-05 2023-11-15
CVE-2023-5344 json Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1969. 7.5 - HIGH 2023-10-02 2023-11-03
CVE-2023-4781 json Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873. 7.8 - HIGH 2023-09-05 2024-02-01
CVE-2023-4752 json Use After Free in GitHub repository vim/vim prior to 9.0.1858. 7.8 - HIGH 2023-09-04 2024-02-01
CVE-2023-4751 json Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331. 7.8 - HIGH 2023-09-03 2023-10-26
CVE-2023-4750 json Use After Free in GitHub repository vim/vim prior to 9.0.1857. 7.8 - HIGH 2023-09-04 2024-02-01

Known software with vulnerabilities from Vim

Type Vendor Product Version
ApplicationVimVim5.6