Gnuplot is a widely embedded command-line graphing utility used across scientific computing, data analysis, and system monitoring contexts, where its parsing of user-supplied input and script execution paths create a notable attack surface despite the product's narrow scope. Vulnerabilities affecting the vendor skew toward serious outcomes, concentrating in memory-safety issues such as NULL-pointer dereferences, buffer overflows, out-of-bounds writes, and uninitialized pointer access that reflect the challenges of handling complex graph specifications and data formats. Defenders should treat Gnuplot instances as potential privilege-escalation or code-execution vectors, particularly where the utility processes untrusted input or runs with elevated permissions; current severity and exploitation data are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gnuplot over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-29369CRITICAL The gnuplot package prior to version 0.1.0 for Node.js allows code execution via shell metacharacters in Gnuplot commands. | May 3, 2021 | 9.8 | 30 | NO | NO |
CVE-2020-25412CRITICAL com_line() in command.c in gnuplot 5.4 leads to an out-of-bounds-write from strncpy() that may lead to arbitrary code execution. | Sep 16, 2020 | 9.8 | 29 | NO | NO |
CVE-2020-25969CRITICAL gnuplot v5.5 was discovered to contain a buffer overflow via the function plotrequest(). | Jul 5, 2023 | 9.8 | 28 | NO | NO |
CVE-2018-19492HIGH An issue was discovered in cairo.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the cairotrm_options function. | Nov 23, 2018 | 7.8 | 25 | NO | NO |
CVE-2018-19491HIGH An issue was discovered in post.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the PS_options function. This f | Nov 23, 2018 | 7.8 | 25 | NO | NO |
CVE-2018-19490HIGH An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue allows an attacker to conduct a heap-based buffer overflow with an arbitrary amount of data in df_generate_ascii_ | Nov 23, 2018 | 7.8 | 25 | NO | NO |
CVE-2017-9670HIGH An uninitialized stack variable vulnerability in load_tic_series() in set.c in gnuplot 5.2.rc1 allows an attacker to cause Denial of Service (Segmentation fault and Memory Corrupti | Jun 15, 2017 | 7.8 | 25 | NO | NO |
CVE-2025-31181MEDIUM A flaw was found in gnuplot. The X11_graphics() function may lead to a segmentation fault and cause a system crash. | Mar 27, 2025 | 6.2 | 20 | NO | NO |
CVE-2021-44917MEDIUM A Divide by Zero vulnerability exists in gnuplot 5.4 in the boundary3d function in graph3d.c, which could cause a Arithmetic exception and application crash. | Dec 21, 2021 | 5.5 | 20 | NO | NO |
CVE-2020-25559HIGH gnuplot 5.5 is affected by double free when executing print_set_output. This may result in context-dependent arbitrary code execution. | Sep 16, 2020 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gnuplot.
Media articles that mention a CVE ID that affects a product developed by Gnuplot — matched by CVE ID, not by vendor name.