Inkscape is a vector graphics editor with a concentrated vulnerability footprint centered on a single widely used application for digital design and illustration work. The recurring weakness classes—including XML external entity injection, pointer-dereference conditions, and out-of-bounds memory access—reflect the complexity of parsing and rendering untrusted file formats, particularly SVG documents that are central to the application's workflow. A moderate tendency toward public exploit availability characterizes this vendor's disclosures; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Inkscape over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-3737MEDIUM Buffer overflow in the SVG importer (style.cpp) of inkscape 0.41 through 0.42.2 might allow remote attackers to execute arbitrary code via a SVG file with long CSS style property v | Nov 22, 2005 | 5.1 | 28 | NO | YES |
CVE-2021-42704HIGH Inkscape version 0.91 is vulnerable to an out-of-bounds write, which may allow an attacker to arbitrary execute code. | May 18, 2022 | 7.8 | 25 | NO | NO |
CVE-2026-4980MEDIUM A local file disclosure vulnerability in the XInclude processing component of Inkscape 1.1 before 1.3 allows a remote attacker to read local files via a crafted SVG file containing | Mar 27, 2026 | 6.3 | 22 | NO | NO |
CVE-2025-15523MEDIUM MacOS version of Inkscape bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permissions
granted by the user to the main application bundle. An | Jan 22, 2026 | 4.8 | 22 | NO | NO |
CVE-2012-5656MEDIUM The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection atta | Jan 18, 2013 | 5.5 | 20 | NO | NO |
CVE-2007-1463MEDIUM Format string vulnerability in Inkscape before 0.45.1 allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a URI, which is not properly h | Mar 21, 2007 | 6.8 | 19 | NO | NO |
CVE-2007-1464MEDIUM Format string vulnerability in the whiteboard Jabber protocol in Inkscape before 0.45.1 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors. | Mar 21, 2007 | 6.8 | 19 | NO | NO |
CVE-2012-6076MEDIUM Inkscape before 0.48.4 reads .eps files from /tmp instead of the current directory, which might cause Inkspace to process unintended files, allow local users to obtain sensitive in | Mar 12, 2013 | 4.4 | 17 | NO | NO |
Inkscape version 0.91 can access an uninitialized pointer, which may allow an attacker to have access to unauthorized information. | May 18, 2022 | 3.3 | 16 | NO | NO |
Inkscape 0.91 is vulnerable to an out-of-bounds read, which may allow an attacker to have access to unauthorized information. | May 18, 2022 | 3.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Inkscape.
Media articles that mention a CVE ID that affects a product developed by Inkscape — matched by CVE ID, not by vendor name.