SWI-Prolog is a logic programming platform with a focused vulnerability footprint centered on the Prolog interpreter itself and its web-based IDE (SWISH), serving an academic and specialized-use community rather than mass deployment. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Swi Prolog over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-6090HIGH Multiple stack-based buffer overflows in the expand function in os/pl-glob.c in SWI-Prolog before 6.2.5 and 6.3.x before 6.3.7 allow remote attackers to cause a denial of service ( | Jan 4, 2013 | 7.5 | 26 | NO | NO |
CVE-2017-17524HIGH library/www_browser.pl in SWI-Prolog 7.2.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers | Dec 14, 2017 | 8.8 | 25 | NO | NO |
CVE-2012-6089HIGH Multiple stack-based buffer overflows in the canoniseFileName function in os/pl-os.c in SWI-Prolog before 6.2.5 and 6.3.x before 6.3.7 allow remote attackers to cause a denial of s | Jan 4, 2013 | 7.5 | 25 | NO | NO |
CVE-2011-2896MEDIUM The LZW decompressor in the LWZReadByte function in giftoppm.c in the David Koblas GIF decoder in PBMPLUS, as used in the gif_read_lzw function in filter/image-gif.c in CUPS before | Aug 19, 2011 | 5.1 | 24 | NO | NO |
CVE-2025-63848MEDIUM Stored cross site scripting (xss) vulnerability in SWISH prolog thru 2.2.0 allowing attackers to execute arbitrary code via crafted web IDE notebook. | Nov 20, 2025 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Swi Prolog.
Media articles that mention a CVE ID that affects a product developed by Swi Prolog — matched by CVE ID, not by vendor name.