CVE-2025-58175GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity Resolution Exploitation status Not known exploited Fix Not confirmed Affected product O org.geoserver.web:gs-web-app Published 06/18/2026 Severity Medium CVE-2025-52465GeoServer has an arbitrary file write vulnerability in its Master Password Dump Page Exploitation status Not known exploited Fix Not confirmed Affected product O org.geoserver.web:gs-web-app Published 06/18/2026 Severity High CVE-2025-27511GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection Exploitation status Not known exploited Fix Not confirmed Affected product O org.geoserver.extension:gs-db2 Published 06/18/2026 Severity High CVE-2025-21621GeoServer Reflected Cross-Site Scripting (XSS) vulnerability in WMS GetFeatureInfo HTML format Exploitation status Not known exploited Fix YesAffected product G geoserver Published 11/25/2025 Severity Medium CVE-2025-58360GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature Exploitation status KEV Fix YesAffected product G geoserver Published 11/25/2025 Severity High CVE-2025-30220GeoTools, GeoServer, and GeoNetwork XML External Entity (XXE) Processing Vulnerability in XSD schema handling Exploitation status Not known exploited Fix YesAffected product G geoserver Published 06/10/2025 Severity Critical CVE-2025-30145GeoServer has an Infinite Loop Vulnerability in Jiffle process Exploitation status Not known exploited Fix YesAffected product G geoserver Published 06/10/2025 Severity High CVE-2025-27505GeoServer Missing Authorization on REST API Index Exploitation status Not known exploited Fix YesAffected product G geoserver Published 06/10/2025 Severity Medium CVE-2024-40625GeoServer Coverage REST API Allows Server Side Request Forgery Exploitation status Not known exploited Fix YesAffected product G geoserver Published 06/10/2025 Severity Medium CVE-2024-38524GWC Home Page communicate version and revision information Exploitation status Not known exploited Fix YesAffected product G geoserver Published 06/10/2025 Severity Medium CVE-2024-34711GeoServer has improper ENTITY_RESOLUTION_ALLOWLIST URI validation in XML Processing (SSRF) Exploitation status Not known exploited Fix Not confirmed Affected product G geoserver Published 06/10/2025 Severity Critical CVE-2024-29198GeoServer Vulnerable to Unauthenticated SSRF via TestWfsPost Exploitation status Not known exploited Fix Not confirmed Affected product G geoserver Published 06/10/2025 Severity High CVE-2024-35230Welcome and About GeoServer pages communicate version and revision information Exploitation status Public exploit Fix YesAffected product G geoserver Published 12/16/2024 Severity Medium CVE-2024-36401Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver Exploitation status KEV Fix Not confirmed Affected product G geoserver Published 07/01/2024 Severity Critical CVE-2024-34696GeoServer's Server Status shows sensitive environmental variables and Java properties Exploitation status Not known exploited Fix Not confirmed Affected product G geoserver Published 07/01/2024 Severity Medium CVE-2024-24749Classpath resource disclosure in GWC Web Resource API on Windows / Tomcat Exploitation status Not known exploited Fix Not confirmed Affected product G geoserver Published 07/01/2024 Severity High CVE-2024-23821GeoServer's GWC Demos Page vulnerable to Stored Cross-Site Scripting (XSS) Exploitation status Not known exploited Fix Not confirmed Affected product G geoserver Published 03/20/2024 Severity Medium CVE-2024-23819GeoServer Stored Cross-Site Scripting (XSS) vulnerability in MapML HTML Page Exploitation status Not known exploited Fix Not confirmed Affected product G geoserver Published 03/20/2024 Severity Medium CVE-2024-23818GeoServer Stored Cross-Site Scripting (XSS) vulnerability in WMS OpenLayers Format Exploitation status Not known exploited Fix Not confirmed Affected product G geoserver Published 03/20/2024 Severity Medium CVE-2024-23643GeoServer Stored Cross-Site Scripting (XSS) vulnerability in GWC Seed Form Exploitation status Public exploit Fix Not confirmed Affected product G geoserver Published 03/20/2024 Severity Medium CVE-2024-23642GeoServer Stored Cross-Site Scripting (XSS) vulnerability in Simple SVG Renderer Exploitation status Not known exploited Fix Not confirmed Affected product G geoserver Published 03/20/2024 Severity Medium CVE-2024-23640GeoServer Stored Cross-Site Scripting (XSS) vulnerability in Style Publisher Exploitation status Not known exploited Fix Not confirmed Affected product G geoserver Published 03/20/2024 Severity Medium CVE-2024-23634GeoServer arbitrary file renaming vulnerability in REST Coverage/Data Store API Exploitation status Not known exploited Fix Not confirmed Affected product G geoserver Published 03/20/2024 Severity Medium CVE-2023-51445GeoServer Stored Cross-Site Scripting (XSS) vulnerability in REST Resources API Exploitation status Public exploit Fix Not confirmed Affected product G geoserver Published 03/20/2024 Severity Medium CVE-2023-51444GeoServer arbitrary file upload vulnerability in REST Coverage Store API Exploitation status Public exploit Fix Not confirmed Affected product G geoserver Published 03/20/2024 Severity High CVE-2023-41877GeoServer log file path traversal vulnerability Exploitation status Not known exploited Fix Not confirmed Affected product G geoserver Published 03/20/2024 Severity High CVE-2023-5786GeoServer GeoWebCache rest.html direct request Exploitation status Public exploit Fix Not confirmed Affected product G GeoWebCache Published 10/26/2023 Severity Medium CVE-2023-43795WPS Server Side Request Forgery in GeoServer Exploitation status Not known exploited Fix YesAffected product G geoserver Published 10/24/2023 Severity High CVE-2023-41339Unsecured WMS dynamic styling sld=<url> parameter affords blind unauthenticated SSRF in GeoServer Exploitation status Not known exploited Fix YesAffected product G geoserver Published 10/24/2023 Severity High CVE-2023-35042Exploitation status Not known exploited Fix Not confirmed Affected product Not confirmed Published 06/12/2023 Severity Unknown CVE-2023-25157Unfiltered SQL Injection Vulnerabilities in Geoserver Exploitation status Not known exploited Fix Not confirmed Affected product G geoserver Published 02/21/2023 Severity Critical CVE-2022-24846Unchecked JNDI lookups in GeoWebCache Exploitation status Not known exploited Fix Not confirmed Affected product G geowebcache Published 04/14/2022 Severity Critical CVE-2022-24847Improper Input Validation in GeoServer Exploitation status Not known exploited Fix Not confirmed Affected product G geoserver Published 04/13/2022 Severity High CVE-2008-7227Exploitation status Not confirmed Fix Not confirmed Affected product Not confirmed Published 09/14/2009 Severity Unknown