Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Swi Prolog

First CVE: Aug 19, 2011Active for: 15 yearsTotal CVEs: 10

SWI-Prolog is a logic programming platform with a focused vulnerability footprint centered on the Prolog interpreter itself and its web-based IDE (SWISH), serving an academic and specialized-use community rather than mass deployment. Current severity, exploitation, and exposure figures are shown alongside this summary.

FAUCET AI Generated
5
Total CVEs
More Total CVEs than 83% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Swi Prolog over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 19, 2011
14 years ago
Most Recent CVE
Nov 20, 2025
246 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (5 CVEs).

5 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-6090HIGH
Multiple stack-based buffer overflows in the expand function in os/pl-glob.c in SWI-Prolog before 6.2.5 and 6.3.x before 6.3.7 allow remote attackers to cause a denial of service (
Jan 4, 20137.526NONO
CVE-2017-17524HIGH
library/www_browser.pl in SWI-Prolog 7.2.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers
Dec 14, 20178.825NONO
CVE-2012-6089HIGH
Multiple stack-based buffer overflows in the canoniseFileName function in os/pl-os.c in SWI-Prolog before 6.2.5 and 6.3.x before 6.3.7 allow remote attackers to cause a denial of s
Jan 4, 20137.525NONO
CVE-2011-2896MEDIUM
The LZW decompressor in the LWZReadByte function in giftoppm.c in the David Koblas GIF decoder in PBMPLUS, as used in the gif_read_lzw function in filter/image-gif.c in CUPS before
Aug 19, 20115.124NONO
CVE-2025-63848MEDIUM
Stored cross site scripting (xss) vulnerability in SWISH prolog thru 2.2.0 allowing attackers to execute arbitrary code via crafted web IDE notebook.
Nov 20, 20256.121NONO
View all 5 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products5 CVEs
40%
60%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network2 (40.0%)
Unknown3 (60.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (40.0%)
High0 (0.0%)
Unknown3 (60.0%)
User Interaction
None0 (0.0%)
Unknown3 (60.0%)
Required2 (40.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None2 (40.0%)
Unknown3 (60.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (5 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Swi Prolog.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Swi Prolog — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Swi Prolog's Products

View all 2 CNAs →

Top CWEs