Emacs

Vendor:

First CVE: Apr 18, 2000 · Active for 26 years

36
Total CVEs
More Total CVEs than 97% of tracked products
2.6
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 25% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Emacs over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 18, 2000
26 years ago
Most Recent CVE
Apr 22, 2026
94 days ago

CVE Severity & Scoring

Emacs36 CVEs
All CVEs352,427 CVEs
LowMediumHighCritical
Attack Vector
Local13 (36.1%)
Network4 (11.1%)
Unknown19 (52.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (47.2%)
High0 (0.0%)
Unknown19 (52.8%)
User Interaction
None6 (16.7%)
Unknown19 (52.8%)
Required11 (30.6%)
Privileges Required
Low5 (13.9%)
High0 (0.0%)
None12 (33.3%)
Unknown19 (52.8%)

Top CVEs

Signals from CVEs in this product scope (36 CVEs).

36 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function i
Feb 20, 20239.830NONO
GNU Emacs before 25.3 allows remote attackers to execute arbitrary code via email with crafted "Content-Type: text/enriched" data containing an x-display XML element that specifies
Sep 14, 20178.829NONO
Untrusted search path vulnerability in EDE in CEDET before 1.0.1, as used in GNU Emacs before 23.4 and other products, allows local users to gain privileges via a crafted Lisp expr
Jan 19, 20129.329NONO
Emacs 21.2.1 does not prompt or warn the user before executing Lisp code in the local variables section of a text file, which allows user-assisted attackers to execute arbitrary co
Dec 31, 20035.129NOYES
In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-command-to-string. This affects Org
Jun 23, 20249.828NONO
emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with unescaped double-quote characters. It is fixed in
Mar 9, 20237.825NONO
emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This is related to lack of compliance with the Desktop
Mar 9, 20237.825NONO
An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection vulnerability. In the hfy-istext-command function, the parameter file and parameter srcdir
Feb 20, 20237.825NONO
GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function i
Nov 28, 20227.825NONO
lisp/files.el in Emacs 23.2, 23.3, 23.4, and 24.1 automatically executes eval forms in local-variable sections when the enable-local-variables option is set to :safe, which allows
Aug 25, 20126.825NONO

Exploit Exposure

Signals from CVEs in this product scope (36 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
5.6% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (36 CVEs).

Media Mentions

Signals from CVEs in this product scope (36 CVEs).

Top CNAs Publishing CVEs For Emacs

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
27.2-8.el917.80.5%00
26.1-9.el817.80.5%00
24.417.52.9%00
24.243.30.3%00
24.154.01.0%00
23.464.91.3%00
23.354.01.0%00
23.264.91.3%00
23.164.50.7%00
22.364.50.7%00
22.264.50.7%00
22.164.50.7%00
21.464.50.8%00
21.3.164.91.3%00
21.374.91.3%00
21.2.164.61.2%01
21.264.50.8%00
21.164.50.8%00
2165.01.0%00
20.764.50.8%00