← Back

Inkscape

inkscape

10 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Inkscape
inkscape

CVEs (10)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Inkscape
1Inkscape
Jun 17, 2026
Mar 27, 2026
N/A· v4
6.3 MEDIUM· v3
N/A· v2
A local file disclosure vulnerability in the XInclude processing component of Inkscape 1.1 before 1.3 allows a remote attacker to read local files via a crafted SVG file containing malicious xi:include tags.
1Inkscape
1Inkscape
Jun 17, 2026
May 18, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Inkscape version 0.91 is vulnerable to an out-of-bounds write, which may allow an attacker to arbitrary execute code.
1Inkscape
1Inkscape
Jun 17, 2026
May 18, 2022
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
Inkscape version 0.91 can access an uninitialized pointer, which may allow an attacker to have access to unauthorized information.
1Inkscape
1Inkscape
Jun 17, 2026
May 18, 2022
N/A· v4
3.3 LOW· v3
3.5 LOW· v2
Inkscape 0.91 is vulnerable to an out-of-bounds read, which may allow an attacker to have access to unauthorized information.
1Inkscape
1Inkscape
Apr 29, 2026
Mar 12, 2013
N/A· v4
N/A· v3
4.4 MEDIUM· v2
Inkscape before 0.48.4 reads .eps files from /tmp instead of the current directory, which might cause Inkspace to process unintended files, allow local users to obtain sensitive information, and possibly have other unspe...Show more
Inkscape before 0.48.4 reads .eps files from /tmp instead of the current directory, which might cause Inkspace to process unintended files, allow local users to obtain sensitive information, and possibly have other unspecified impacts.Show less
4Canonical
FedoraprojectInkscape+1 more
4Fedora
InkscapeOpensuse+1 more
Apr 29, 2026
Jan 18, 2013
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.
1Inkscape
1Inkscape
Apr 23, 2026
Mar 21, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Format string vulnerability in the whiteboard Jabber protocol in Inkscape before 0.45.1 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors.
1Inkscape
1Inkscape
Apr 23, 2026
Mar 21, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Format string vulnerability in Inkscape before 0.45.1 allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a URI, which is not properly handled by certain dialogs.
1Inkscape
1Inkscape
Apr 16, 2026
Nov 29, 2005
N/A· v4
N/A· v3
2.1 LOW· v2
The ps2epsi extension shell script (ps2epsi.sh) in Inkscape before 0.41 allows local users to overwrite arbitrary files via a symlink attack on the tmpepsifile.epsi temporary file.
1Inkscape
1Inkscape
Apr 16, 2026
Nov 22, 2005
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Buffer overflow in the SVG importer (style.cpp) of inkscape 0.41 through 0.42.2 might allow remote attackers to execute arbitrary code via a SVG file with long CSS style property values.