{"schema_version":1,"title":"Vim vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 38 vulnerabilities in Vim: 0 in the last 7 days and 13 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-73078, was published on 11 August 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/vim","json_url":"https://junglewise.ai/threats/vendors/vim.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/vim","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":3,"all_time":38,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":13,"last_365_days":38},"latest":[{"cve":"CVE-2026-73078","cvss":6.1,"epss":0.0034,"slug":"cve-2026-73078-vim-netrw-code-injection-via-menu-construction","title":"Vim netrw code injection via menu construction","severity":"info","exploited":false,"published_at":"2026-08-11T16:17:39.573+00:00","url":"https://junglewise.ai/threats/cve-2026-73078-vim-netrw-code-injection-via-menu-construction"},{"cve":"CVE-2026-73077","cvss":6.3,"epss":0.0014,"slug":"cve-2026-73077-vim-shell-filetype-plugin-os-command-injection-via-keyword-lookup","title":"Vim shell filetype plugin OS command injection via keyword lookup","severity":"info","exploited":false,"published_at":"2026-08-11T16:17:39.43+00:00","url":"https://junglewise.ai/threats/cve-2026-73077-vim-shell-filetype-plugin-os-command-injection-via-keyword-lookup"},{"cve":"CVE-2026-73076","cvss":6.3,"epss":0.0013,"slug":"cve-2026-73076-vim-vimball-arbitrary-command-execution-via-vimballrecord","title":"Vim vimball arbitrary command execution via .VimballRecord","severity":"info","exploited":false,"published_at":"2026-08-11T16:17:38.98+00:00","url":"https://junglewise.ai/threats/cve-2026-73076-vim-vimball-arbitrary-command-execution-via-vimballrecord"},{"cve":"CVE-2026-73075","cvss":6.2,"epss":0.0017,"slug":"cve-2026-73075-vim-out-of-bounds-access-in-popup-opacity-handling","title":"Vim out-of-bounds access in popup opacity handling","severity":"info","exploited":false,"published_at":"2026-08-11T16:17:38.84+00:00","url":"https://junglewise.ai/threats/cve-2026-73075-vim-out-of-bounds-access-in-popup-opacity-handling"},{"cve":"CVE-2026-73074","cvss":6.5,"epss":0.0015,"slug":"cve-2026-73074-vim-heap-overflow-in-text-property-handling","title":"Vim heap overflow in text property handling","severity":"info","exploited":false,"published_at":"2026-08-11T16:17:38.697+00:00","url":"https://junglewise.ai/threats/cve-2026-73074-vim-heap-overflow-in-text-property-handling"},{"cve":"CVE-2026-73072","cvss":7.3,"epss":0.0013,"slug":"cve-2026-73072-vim-heap-buffer-overflow-in-spell-file-parsing","title":"Vim heap buffer overflow in spell file parsing","severity":"info","exploited":false,"published_at":"2026-08-11T16:17:38.553+00:00","url":"https://junglewise.ai/threats/cve-2026-73072-vim-heap-buffer-overflow-in-spell-file-parsing"},{"cve":"CVE-2026-73071","cvss":3.3,"epss":0.0016,"slug":"cve-2026-73071-vim-use-after-free-in-json-decoder","title":"Vim use-after-free in JSON decoder","severity":"low","exploited":false,"published_at":"2026-08-11T16:17:38.413+00:00","url":"https://junglewise.ai/threats/cve-2026-73071-vim-use-after-free-in-json-decoder"},{"cve":"CVE-2026-73070","cvss":5.5,"epss":0.0019,"slug":"cve-2026-73070-vim-stack-buffer-overflow-in-socket-server","title":"Vim stack buffer overflow in socket server","severity":"medium","exploited":false,"published_at":"2026-08-11T16:17:38.257+00:00","url":"https://junglewise.ai/threats/cve-2026-73070-vim-stack-buffer-overflow-in-socket-server"},{"cve":"CVE-2026-51401","cvss":7.7,"epss":0.002,"slug":"cve-2026-51401-vim-vms-fixfilename-null-pointer-dereference","title":"Vim vms_fixfilename NULL pointer dereference","severity":"high","exploited":false,"published_at":"2026-08-04T21:16:36.567+00:00","url":"https://junglewise.ai/threats/cve-2026-51401-vim-vms-fixfilename-null-pointer-dereference"},{"cve":"CVE-2026-51400","cvss":8.4,"epss":0.0018,"slug":"cve-2026-51400-vim-memory-leak-in-vms-fixfilename","title":"Vim memory leak in vms_fixfilename()","severity":"high","exploited":false,"published_at":"2026-08-04T21:16:36.433+00:00","url":"https://junglewise.ai/threats/cve-2026-51400-vim-memory-leak-in-vms-fixfilename"},{"cve":"CVE-2026-59858","cvss":8.4,"slug":"cve-2026-59858-vim-arbitrary-command-execution-in-c-omni-completion","title":"Vim arbitrary command execution in C omni-completion","severity":"info","exploited":false,"published_at":"2026-07-09T23:17:06.74+00:00","url":"https://junglewise.ai/threats/cve-2026-59858-vim-arbitrary-command-execution-in-c-omni-completion"},{"cve":"CVE-2026-59857","cvss":5.6,"slug":"cve-2026-59857-vim-stack-out-of-bounds-write-in-spell-soundfold-sal","title":"Vim stack out-of-bounds write in spell_soundfold_sal","severity":"info","exploited":false,"published_at":"2026-07-09T23:17:06.58+00:00","url":"https://junglewise.ai/threats/cve-2026-59857-vim-stack-out-of-bounds-write-in-spell-soundfold-sal"},{"cve":"CVE-2026-59856","cvss":8.4,"slug":"cve-2026-59856-vim-command-injection-in-php-omni-completion","title":"Vim command injection in PHP omni-completion","severity":"info","exploited":false,"published_at":"2026-07-09T23:17:06.42+00:00","url":"https://junglewise.ai/threats/cve-2026-59856-vim-command-injection-in-php-omni-completion"},{"cve":"CVE-2026-57456","cvss":8.4,"slug":"cve-2026-57456-vim-code-injection-in-python-omni-completion-docstrings","title":"Vim code injection in Python omni-completion docstrings","severity":"info","exploited":false,"published_at":"2026-06-25T16:16:42.9+00:00","url":"https://junglewise.ai/threats/cve-2026-57456-vim-code-injection-in-python-omni-completion-docstrings"},{"cve":"CVE-2026-57455","cvss":5.4,"slug":"cve-2026-57455-vim-stack-out-of-bounds-write-in-spell-soundfold-sofo","title":"Vim stack out-of-bounds write in spell_soundfold_sofo","severity":"info","exploited":false,"published_at":"2026-06-25T16:16:42.773+00:00","url":"https://junglewise.ai/threats/cve-2026-57455-vim-stack-out-of-bounds-write-in-spell-soundfold-sofo"},{"cve":"CVE-2026-57454","cvss":6.8,"slug":"cve-2026-57454-vim-out-of-bounds-read-in-virtual-text-property-handling","title":"Vim out-of-bounds read in virtual-text property handling","severity":"info","exploited":false,"published_at":"2026-06-25T16:16:42.647+00:00","url":"https://junglewise.ai/threats/cve-2026-57454-vim-out-of-bounds-read-in-virtual-text-property-handling"},{"cve":"CVE-2026-57453","cvss":6.5,"slug":"cve-2026-57453-vim-command-injection-in-zip-vim-plugin-via-powershell-fallback","title":"Vim command injection in zip.vim plugin via PowerShell fallback","severity":"medium","exploited":false,"published_at":"2026-06-25T16:16:42.52+00:00","url":"https://junglewise.ai/threats/cve-2026-57453-vim-command-injection-in-zip-vim-plugin-via-powershell-fallback"},{"cve":"CVE-2026-57452","cvss":5.5,"slug":"cve-2026-57452-vim-out-of-bounds-read-in-libsodium-encrypted-file-parsing","title":"Vim out-of-bounds read in libsodium-encrypted file parsing","severity":"medium","exploited":false,"published_at":"2026-06-25T16:16:42.397+00:00","url":"https://junglewise.ai/threats/cve-2026-57452-vim-out-of-bounds-read-in-libsodium-encrypted-file-parsing"},{"cve":"CVE-2026-57451","cvss":5.3,"slug":"cve-2026-57451-vim-out-of-bounds-read-in-get-text-props-via-crafted-undo-file","title":"Vim out-of-bounds read in get_text_props via crafted undo file","severity":"medium","exploited":false,"published_at":"2026-06-25T16:16:42.263+00:00","url":"https://junglewise.ai/threats/cve-2026-57451-vim-out-of-bounds-read-in-get-text-props-via-crafted-undo-file"},{"cve":"CVE-2026-55895","cvss":5.7,"slug":"cve-2026-55895-vim-code-injection-in-netrw-plugin-via-crafted-filename","title":"Vim code injection in netrw plugin via crafted filename","severity":"info","exploited":false,"published_at":"2026-06-25T16:16:41.077+00:00","url":"https://junglewise.ai/threats/cve-2026-55895-vim-code-injection-in-netrw-plugin-via-crafted-filename"},{"cve":"CVE-2026-55892","cvss":5.5,"slug":"cve-2026-55892-vim-stack-out-of-bounds-write-in-dump-prefixes","title":"Vim stack out-of-bounds write in dump_prefixes","severity":"medium","exploited":false,"published_at":"2026-06-25T16:16:40.69+00:00","url":"https://junglewise.ai/threats/cve-2026-55892-vim-stack-out-of-bounds-write-in-dump-prefixes"},{"cve":"CVE-2026-55693","cvss":5.7,"slug":"cve-2026-55693-vim-stack-out-of-bounds-write-in-tree-count-words","title":"Vim stack out-of-bounds write in tree_count_words","severity":"info","exploited":false,"published_at":"2026-06-25T16:16:40.22+00:00","url":"https://junglewise.ai/threats/cve-2026-55693-vim-stack-out-of-bounds-write-in-tree-count-words"},{"cve":"CVE-2026-52860","cvss":7.5,"slug":"cve-2026-52860-vim-python-omni-completion-code-injection-in-function-and-class","title":"Vim Python omni-completion code injection in function and class definitions","severity":"info","exploited":false,"published_at":"2026-06-11T19:16:47.773+00:00","url":"https://junglewise.ai/threats/cve-2026-52860-vim-python-omni-completion-code-injection-in-function-and-class"},{"cve":"CVE-2026-52859","cvss":6.9,"slug":"cve-2026-52859-vim-out-of-bounds-read-in-update-snapshot-function","title":"Vim out-of-bounds read in update_snapshot function","severity":"info","exploited":false,"published_at":"2026-06-11T19:16:47.627+00:00","url":"https://junglewise.ai/threats/cve-2026-52859-vim-out-of-bounds-read-in-update-snapshot-function"},{"cve":"CVE-2026-52858","cvss":7.3,"slug":"cve-2026-52858-vim-arbitrary-code-execution-in-python-omni-completion","title":"Vim arbitrary code execution in Python omni-completion","severity":"info","exploited":false,"published_at":"2026-06-11T19:16:47.487+00:00","url":"https://junglewise.ai/threats/cve-2026-52858-vim-arbitrary-code-execution-in-python-omni-completion"}],"vendor":{"hub":true,"name":"Vim","slug":"vim","homepage":"https://www.vim.org/","description":"Vim is the developer of the Vim text editor and related software projects.","url":"https://junglewise.ai/threats/vendors/vim"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":8},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-34714","cvss":9.2,"epss":0.0054,"slug":"cve-2026-34714-vim-code-execution-via-tabpanel-modeline-escape-and-sandbox","title":"Vim code execution via tabpanel modeline escape and sandbox bypass","severity":"critical","exploited":false,"published_at":"2026-03-30T19:16:26.853+00:00","url":"https://junglewise.ai/threats/cve-2026-34714-vim-code-execution-via-tabpanel-modeline-escape-and-sandbox"},{"cve":"CVE-2026-51400","cvss":8.4,"epss":0.0018,"slug":"cve-2026-51400-vim-memory-leak-in-vms-fixfilename","title":"Vim memory leak in vms_fixfilename()","severity":"high","exploited":false,"published_at":"2026-08-04T21:16:36.433+00:00","url":"https://junglewise.ai/threats/cve-2026-51400-vim-memory-leak-in-vms-fixfilename"},{"cve":"CVE-2026-34982","cvss":8.2,"epss":0.0042,"slug":"cve-2026-34982-vim-modeline-sandbox-bypass-in-multiple-options","title":"Vim modeline sandbox bypass in multiple options","severity":"high","exploited":false,"published_at":"2026-04-06T16:16:38.777+00:00","url":"https://junglewise.ai/threats/cve-2026-34982-vim-modeline-sandbox-bypass-in-multiple-options"},{"cve":"CVE-2026-51401","cvss":7.7,"epss":0.002,"slug":"cve-2026-51401-vim-vms-fixfilename-null-pointer-dereference","title":"Vim vms_fixfilename NULL pointer dereference","severity":"high","exploited":false,"published_at":"2026-08-04T21:16:36.567+00:00","url":"https://junglewise.ai/threats/cve-2026-51401-vim-vms-fixfilename-null-pointer-dereference"},{"cve":"CVE-2026-25749","cvss":6.6,"epss":0.0001,"slug":"cve-2026-25749-vim-heap-buffer-overflow-in-helpfile-option-handling","title":"Vim heap buffer overflow in helpfile option handling","severity":"medium","exploited":false,"published_at":"2026-02-06T23:15:54.23+00:00","url":"https://junglewise.ai/threats/cve-2026-25749-vim-heap-buffer-overflow-in-helpfile-option-handling"},{"cve":"CVE-2026-45130","cvss":6.6,"epss":0,"slug":"cve-2026-45130-vim-heap-buffer-overflow-in-spell-file-loading","title":"Vim heap buffer overflow in spell file loading","severity":"medium","exploited":false,"published_at":"2026-05-08T23:16:40.053+00:00","url":"https://junglewise.ai/threats/cve-2026-45130-vim-heap-buffer-overflow-in-spell-file-loading"},{"cve":"CVE-2026-57453","cvss":6.5,"slug":"cve-2026-57453-vim-command-injection-in-zip-vim-plugin-via-powershell-fallback","title":"Vim command injection in zip.vim plugin via PowerShell fallback","severity":"medium","exploited":false,"published_at":"2026-06-25T16:16:42.52+00:00","url":"https://junglewise.ai/threats/cve-2026-57453-vim-command-injection-in-zip-vim-plugin-via-powershell-fallback"},{"cve":"CVE-2026-33412","cvss":5.6,"epss":0.0073,"slug":"cve-2026-33412-vim-command-injection-in-glob-function-via-newline-character","title":"Vim command injection in glob function via newline character","severity":"medium","exploited":false,"published_at":"2026-03-24T20:16:29.74+00:00","url":"https://junglewise.ai/threats/cve-2026-33412-vim-command-injection-in-glob-function-via-newline-character"},{"cve":"CVE-2026-73070","cvss":5.5,"epss":0.0019,"slug":"cve-2026-73070-vim-stack-buffer-overflow-in-socket-server","title":"Vim stack buffer overflow in socket server","severity":"medium","exploited":false,"published_at":"2026-08-11T16:17:38.257+00:00","url":"https://junglewise.ai/threats/cve-2026-73070-vim-stack-buffer-overflow-in-socket-server"},{"cve":"CVE-2026-57452","cvss":5.5,"slug":"cve-2026-57452-vim-out-of-bounds-read-in-libsodium-encrypted-file-parsing","title":"Vim out-of-bounds read in libsodium-encrypted file parsing","severity":"medium","exploited":false,"published_at":"2026-06-25T16:16:42.397+00:00","url":"https://junglewise.ai/threats/cve-2026-57452-vim-out-of-bounds-read-in-libsodium-encrypted-file-parsing"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"name":"Vim","slug":"vim","vulnerabilities":38,"url":"https://junglewise.ai/threats/technologies/vim"}]}