Gnuplot is a command-driven graphing and data-visualization utility with a narrow product footprint, where the observed vulnerability signal centers on OS command injection arising from improper neutralization of special elements in command processing. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gnuplot Project over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-29369CRITICAL The gnuplot package prior to version 0.1.0 for Node.js allows code execution via shell metacharacters in Gnuplot commands. | May 3, 2021 | 9.8 | 30 | NO | NO |
CVE-2020-25412CRITICAL com_line() in command.c in gnuplot 5.4 leads to an out-of-bounds-write from strncpy() that may lead to arbitrary code execution. | Sep 16, 2020 | 9.8 | 29 | NO | NO |
CVE-2020-25969CRITICAL gnuplot v5.5 was discovered to contain a buffer overflow via the function plotrequest(). | Jul 5, 2023 | 9.8 | 28 | NO | NO |
CVE-2018-19492HIGH An issue was discovered in cairo.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the cairotrm_options function. | Nov 23, 2018 | 7.8 | 25 | NO | NO |
CVE-2018-19491HIGH An issue was discovered in post.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the PS_options function. This f | Nov 23, 2018 | 7.8 | 25 | NO | NO |
CVE-2018-19490HIGH An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue allows an attacker to conduct a heap-based buffer overflow with an arbitrary amount of data in df_generate_ascii_ | Nov 23, 2018 | 7.8 | 25 | NO | NO |
CVE-2017-9670HIGH An uninitialized stack variable vulnerability in load_tic_series() in set.c in gnuplot 5.2.rc1 allows an attacker to cause Denial of Service (Segmentation fault and Memory Corrupti | Jun 15, 2017 | 7.8 | 25 | NO | NO |
CVE-2025-31181MEDIUM A flaw was found in gnuplot. The X11_graphics() function may lead to a segmentation fault and cause a system crash. | Mar 27, 2025 | 6.2 | 20 | NO | NO |
CVE-2025-31180MEDIUM A flaw was found in gnuplot. The CANVAS_text() function may lead to a segmentation fault and cause a system crash. | Mar 27, 2025 | 6.2 | 20 | NO | NO |
CVE-2025-31179MEDIUM A flaw was found in gnuplot. The xstrftime() function may lead to a segmentation fault, causing a system crash. | Mar 27, 2025 | 6.2 | 20 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gnuplot Project.
Media articles that mention a CVE ID that affects a product developed by Gnuplot Project — matched by CVE ID, not by vendor name.