Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Vim — Vulnerabilities & Security Advisories 66

All 66 CVE vulnerabilities found in Vim, with AI-generated Chinese analysis, references, and POCs.

This page details security weaknesses affecting the vim text editor, a widely used cross-platform command-line text editor. It aggregates known vulnerabilities related to this specific software, focusing on the Common Weakness Enumeration (CWE) classifications associated with its codebase and release history. The collection encompasses a broad spectrum of security flaws, including buffer overflows, use-after-free errors, integer overflows, and injection vulnerabilities that may allow remote code execution or denial of service. The data covers historical records from the earliest tracked incidents up to the most recent disclosures, providing a comprehensive timeline of security issues. Readers can utilize this resource to track vendor advisories and patches issued for vim over time. It also serves as a reference for understanding the prevalence and nature of specific weakness classes within the application’s development lifecycle. Furthermore, users can look up the product’s vulnerability history to assess risk trends and prioritize mitigation efforts. This aggregation aims to support security analysts, developers, and system administrators in identifying and addressing potential exposure points. By centralizing this information, the page facilitates a clearer view of the security posture of vim, enabling informed decisions regarding updates and configuration hardening. The content is organized to help users navigate from high-level vulnerability types to specific implementation details without requiring prior deep knowledge of the underlying code structure.

Vendor: unspecified

CVE IDTitleCVSSSeverityPublished
CVE-2026-59856 Vim: Arbitrary Code Execution via PHP Omni-Completion CWE-94--2026-07-09
CVE-2026-59858 Vim: Arbitrary Code Execution via C Omni-Completion CWE-94--2026-07-09
CVE-2026-59857 Vim: Out-of-bounds Write in SAL Soundfolding CWE-787--2026-07-09
CVE-2026-55693 Vim: Out-of-bounds Write in Spell File Word Count CWE-787--2026-06-25
CVE-2026-55892 Vim: Out-of-bounds Write in Spell File Prefix Dump CWE-787 5.5 Medium2026-06-25
CVE-2026-55895 Vim: Vimscript Code Injection in netrw NetrwLocalRmFile() via crafted filename CWE-78--2026-06-25
CVE-2026-57451 Vim: Out-of-bounds Read in Text Property Count CWE-125 5.3 Medium2026-06-25
CVE-2026-57452 Vim: Out-of-bounds Read with libsodium-encrypted Files CWE-125 5.5 Medium2026-06-25
CVE-2026-57453 Vim: PowerShell Command Injection via Unescaped Filename in zip.vim Extraction CWE-77 6.5 Medium2026-06-25
CVE-2026-57454 Vim: Out-of-bounds Read with Text Properties CWE-125--2026-06-25
CVE-2026-57455 Vim: Stack out-of-bounds write in `spell_soundfold_sofo()` via an over-length `soundfold()` argument CWE-787--2026-06-25
CVE-2026-57456 Vim: Arbitrary Code Execution via Python Omni-Completion Docstrings CWE-94--2026-06-25
CVE-2026-52860 Vim: Arbitrary Code Execution via Python Omni-Completion CWE-94--2026-06-11
CVE-2026-52859 Vim: Out-of-bounds Read in Terminal Screen Snapshot CWE-125--2026-06-11
CVE-2026-52858 Vim: Arbitrary Code Execution via Python Omni-Completion CWE-94--2026-06-11
CVE-2026-47162 Vim: Vimscript Code Injection in netrw NetrwBookHistSave() via crafted directory name CWE-74--2026-06-11
CVE-2026-47167 Vim: Vimscript Code Injection in cucumber filetype plugin via crafted step-definition regex CWE-94--2026-06-11
CVE-2026-46483 Vim: Command injection in tar#Vimuntar via missing shellescape {special} flag CWE-78 3.6 Low2026-05-15
CVE-2026-45130 Vim: Heap Buffer Overflow in spell file loading CWE-122 6.6 Medium2026-05-08
CVE-2026-44656 Vim: OS Command Injection via 'path' completion CWE-78 7.8AIHighAI2026-05-08
CVE-2026-42307 Vim: OS Command Injection in netrw CWE-78 4.4 Medium2026-05-08
CVE-2026-41411 Vim: Command injection via backtick expansion in tag filenames CWE-78 6.6 Medium2026-04-24
CVE-2026-39881 Vim Ex command injection in Vims NetBeans integration CWE-94 5.0 Medium2026-04-08
CVE-2026-35177 Path traversal issue with zip.vim in Vim CWE-22 4.1 Medium2026-04-06
CVE-2026-34982 Vim modeline bypass via various options affects Vim < 9.2.0276 CWE-78 8.2 High2026-04-06
CVE-2026-34714 Vim 操作系统命令注入漏洞 CWE-78 9.2 Critical2026-03-30
CVE-2026-33412 Vim affected by Command injection via newline in glob() CWE-78 5.6 Medium2026-03-24
CVE-2026-32249 NFA regex engine NULL pointer dereference affects Vim < 9.2.0137 CWE-476 5.3 Medium2026-03-12
CVE-2026-28422 Vim has stack-buffer-overflow in build_stl_str_hl() CWE-121 2.2 Low2026-02-27
CVE-2026-28421 Vim has a heap-buffer-overflow and a segmentation fault CWE-20 5.3 Medium2026-02-27

All 66 known CVE vulnerabilities affecting Vim with full Chinese analysis, references, and POCs where available.