VendorsNullsoftnullsoft_scriptable_install_systemany version
Vulnerabilities

Nullsoft Scriptable Install System (NSIS) any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2015-9268
Nullsoft Scriptable Install System (NSIS) before 2.49 has unsafe implicit linking against Version.dll. In other words, there is no protection mechanism in which a wrapper function resolves the dependency at an appropriate time during runtime.
Published 2018-10-01 · Modified
9.3EPSS 0.015
CVE-2026-42171
NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attackers to gain privileges (if they can cause my_GetTempFileName to return 0, as shown in the references).
Published 2026-04-24 · Analyzed
7.8EPSS 0.002
CVE-2015-9267
Nullsoft Scriptable Install System (NSIS) before 2.49 uses temporary folder locations that allow unprivileged local users to overwrite files. This allows a local attack in which either a plugin or the uninstaller can be replaced by a Trojan horse program.
Published 2018-10-01 · Modified
5.5EPSS 0.004
CVE-2023-37378
Nullsoft Scriptable Install System (NSIS) before 3.09 mishandles access control for an uninstaller directory.
Published 2023-07-03 · Modified
5.3EPSS 0.009