CVEs we hold for Geoserver
Records whose assigning authority named Geoserver as the affected vendor. Newest identifiers first, capped at 200.
CVE-2025-58360GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap featuregeoserver
CVE-2025-58175GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity Resolutiongeoserver org.geoserver:gs-main
CVE-2025-52465GeoServer has an arbitrary file write vulnerability in its Master Password Dump Pagegeoserver org.geoserver.web:gs-web-sec-core
CVE-2025-30220GeoTools, GeoServer, and GeoNetwork XML External Entity (XXE) Processing Vulnerability in XSD schema handlinggeoserver
CVE-2025-27511GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connectiongeoserver org.geoserver.extension:gs-db2
CVE-2025-21621GeoServer Reflected Cross-Site Scripting (XSS) vulnerability in WMS GetFeatureInfo HTML formatgeoserver
CVE-2024-36401Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoservergeoserver
CVE-2024-35230Welcome and About GeoServer pages communicate version and revision informationgeoserver
CVE-2024-34711GeoServer has improper ENTITY_RESOLUTION_ALLOWLIST URI validation in XML Processing (SSRF)geoserver
CVE-2024-34696GeoServer's Server Status shows sensitive environmental variables and Java propertiesgeoserver
CVE-2024-23818GeoServer Stored Cross-Site Scripting (XSS) vulnerability in WMS OpenLayers Formatgeoserver
CVE-2024-23642GeoServer Stored Cross-Site Scripting (XSS) vulnerability in Simple SVG Renderergeoserver
CVE-2024-23634GeoServer arbitrary file renaming vulnerability in REST Coverage/Data Store APIgeoserver
CVE-2023-51445GeoServer Stored Cross-Site Scripting (XSS) vulnerability in REST Resources APIgeoserver
CVE-2023-41339Unsecured WMS dynamic styling sld=<url> parameter affords blind unauthenticated SSRF in GeoServergeoserver
31 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.