Vendor
Vim vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 38 vulnerabilities in Vim: 0 in the last 7 days and 13 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-73078, was published on 11 August 2026. 1 technology has a page of its own.
- Last 7 days
- 0
- Last 90 days
- 13
- Critical, all time
- 1
- Exploited in the wild
- 0
About Vim
Vim is the developer of the Vim text editor and related software projects.
Vim technologies
- Vim38
Latest Vim vulnerabilities
- CVE-2026-73078: Vim netrw code injection via menu constructioninfoCVSS 6.1EPSS 0.3%
- CVE-2026-73077: Vim shell filetype plugin OS command injection via keyword lookupinfoCVSS 6.3EPSS 0.1%
- CVE-2026-73076: Vim vimball arbitrary command execution via .VimballRecordinfoCVSS 6.3EPSS 0.1%
- CVE-2026-73075: Vim out-of-bounds access in popup opacity handlinginfoCVSS 6.2EPSS 0.2%
- CVE-2026-73074: Vim heap overflow in text property handlinginfoCVSS 6.5EPSS 0.1%
- CVE-2026-73072: Vim heap buffer overflow in spell file parsinginfoCVSS 7.3EPSS 0.1%
- CVE-2026-73071: Vim use-after-free in JSON decoderlowCVSS 3.3EPSS 0.2%
- CVE-2026-73070: Vim stack buffer overflow in socket servermediumCVSS 5.5EPSS 0.2%
- CVE-2026-51401: Vim vms_fixfilename NULL pointer dereferencehighCVSS 7.7EPSS 0.2%
- CVE-2026-51400: Vim memory leak in vms_fixfilename()highCVSS 8.4EPSS 0.2%
- CVE-2026-59858: Vim arbitrary command execution in C omni-completioninfoCVSS 8.4
- CVE-2026-59857: Vim stack out-of-bounds write in spell_soundfold_salinfoCVSS 5.6
- CVE-2026-59856: Vim command injection in PHP omni-completioninfoCVSS 8.4
- CVE-2026-57456: Vim code injection in Python omni-completion docstringsinfoCVSS 8.4
- CVE-2026-57455: Vim stack out-of-bounds write in spell_soundfold_sofoinfoCVSS 5.4
- CVE-2026-57454: Vim out-of-bounds read in virtual-text property handlinginfoCVSS 6.8
- CVE-2026-57453: Vim command injection in zip.vim plugin via PowerShell fallbackmediumCVSS 6.5
- CVE-2026-57452: Vim out-of-bounds read in libsodium-encrypted file parsingmediumCVSS 5.5
- CVE-2026-57451: Vim out-of-bounds read in get_text_props via crafted undo filemediumCVSS 5.3
- CVE-2026-55895: Vim code injection in netrw plugin via crafted filenameinfoCVSS 5.7
- CVE-2026-55892: Vim stack out-of-bounds write in dump_prefixesmediumCVSS 5.5
- CVE-2026-55693: Vim stack out-of-bounds write in tree_count_wordsinfoCVSS 5.7
- CVE-2026-52860: Vim Python omni-completion code injection in function and class definitionsinfoCVSS 7.5
- CVE-2026-52859: Vim out-of-bounds read in update_snapshot functioninfoCVSS 6.9
- CVE-2026-52858: Vim arbitrary code execution in Python omni-completioninfoCVSS 7.3
Most severe Vim vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-34714: Vim code execution via tabpanel modeline escape and sandbox bypasscriticalCVSS 9.2EPSS 0.5%
- CVE-2026-51400: Vim memory leak in vms_fixfilename()highCVSS 8.4EPSS 0.2%
- CVE-2026-34982: Vim modeline sandbox bypass in multiple optionshighCVSS 8.2EPSS 0.4%
- CVE-2026-51401: Vim vms_fixfilename NULL pointer dereferencehighCVSS 7.7EPSS 0.2%
- CVE-2026-25749: Vim heap buffer overflow in helpfile option handlingmediumCVSS 6.6EPSS 0.0%
- CVE-2026-45130: Vim heap buffer overflow in spell file loadingmediumCVSS 6.6EPSS 0.0%
- CVE-2026-57453: Vim command injection in zip.vim plugin via PowerShell fallbackmediumCVSS 6.5
- CVE-2026-33412: Vim command injection in glob function via newline charactermediumCVSS 5.6EPSS 0.7%
- CVE-2026-73070: Vim stack buffer overflow in socket servermediumCVSS 5.5EPSS 0.2%
- CVE-2026-57452: Vim out-of-bounds read in libsodium-encrypted file parsingmediumCVSS 5.5
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 3 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 2 | 0 | |
| 10 Aug 2026 | 8 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/vim.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Vim vulnerabilities", https://junglewise.ai/threats/vendors/vim, 26 September 2026.