geoserver
geoserver- Product type
- Other
- Catalog vulnerabilities
- 29
Severity across 27 analyzed records
en
Verify to analyze this security profile
As of 09/14/2026, within CyStack's analyzed data, geoserver has 0 security vulnerabilities published in the last 90 days. Of these, 0 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of geoserver and determine which vulnerabilities affect that version.
| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2025-21621GeoServer Reflected Cross-Site Scripting (XSS) vulnerability in WMS GetFeatureInfo HTML format | Exploitation statusNot known exploited | FixYes | Published11/25/2025 | SeverityMedium |
CVE-2025-58360GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature | Exploitation statusKEV | FixYes | Published11/25/2025 | SeverityHigh |
CVE-2025-30220GeoTools, GeoServer, and GeoNetwork XML External Entity (XXE) Processing Vulnerability in XSD schema handling | Exploitation statusNot known exploited | FixYes | Published06/10/2025 | SeverityCritical |
CVE-2025-30145GeoServer has an Infinite Loop Vulnerability in Jiffle process | Exploitation statusNot known exploited | FixYes | Published06/10/2025 | SeverityHigh |
CVE-2025-27505GeoServer Missing Authorization on REST API Index | Exploitation statusNot known exploited | FixYes | Published06/10/2025 | SeverityMedium |
CVE-2024-40625GeoServer Coverage REST API Allows Server Side Request Forgery | Exploitation statusNot known exploited | FixYes | Published06/10/2025 | SeverityMedium |
CVE-2024-38524GWC Home Page communicate version and revision information | Exploitation statusNot known exploited | FixYes | Published06/10/2025 | SeverityMedium |
CVE-2024-34711GeoServer has improper ENTITY_RESOLUTION_ALLOWLIST URI validation in XML Processing (SSRF) | Exploitation statusNot known exploited | FixNot confirmed | Published06/10/2025 | SeverityCritical |
CVE-2024-29198GeoServer Vulnerable to Unauthenticated SSRF via TestWfsPost | Exploitation statusNot known exploited | FixNot confirmed | Published06/10/2025 | SeverityHigh |
CVE-2024-35230Welcome and About GeoServer pages communicate version and revision information | Exploitation statusPublic exploit | FixYes | Published12/16/2024 | SeverityMedium |
CVE-2024-36401Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver | Exploitation statusKEV | FixNot confirmed | Published07/01/2024 | SeverityCritical |
CVE-2024-34696GeoServer's Server Status shows sensitive environmental variables and Java properties | Exploitation statusNot known exploited | FixNot confirmed | Published07/01/2024 | SeverityMedium |
CVE-2024-24749Classpath resource disclosure in GWC Web Resource API on Windows / Tomcat | Exploitation statusNot known exploited | FixNot confirmed | Published07/01/2024 | SeverityHigh |
CVE-2024-23821GeoServer's GWC Demos Page vulnerable to Stored Cross-Site Scripting (XSS) | Exploitation statusNot known exploited | FixNot confirmed | Published03/20/2024 | SeverityMedium |
CVE-2024-23819GeoServer Stored Cross-Site Scripting (XSS) vulnerability in MapML HTML Page | Exploitation statusNot known exploited | FixNot confirmed | Published03/20/2024 | SeverityMedium |
CVE-2024-23818GeoServer Stored Cross-Site Scripting (XSS) vulnerability in WMS OpenLayers Format | Exploitation statusNot known exploited | FixNot confirmed | Published03/20/2024 | SeverityMedium |
CVE-2024-23643GeoServer Stored Cross-Site Scripting (XSS) vulnerability in GWC Seed Form | Exploitation statusPublic exploit | FixNot confirmed | Published03/20/2024 | SeverityMedium |
CVE-2024-23642GeoServer Stored Cross-Site Scripting (XSS) vulnerability in Simple SVG Renderer | Exploitation statusNot known exploited | FixNot confirmed | Published03/20/2024 | SeverityMedium |
CVE-2024-23640GeoServer Stored Cross-Site Scripting (XSS) vulnerability in Style Publisher | Exploitation statusNot known exploited | FixNot confirmed | Published03/20/2024 | SeverityMedium |
CVE-2024-23634GeoServer arbitrary file renaming vulnerability in REST Coverage/Data Store API | Exploitation statusNot known exploited | FixNot confirmed | Published03/20/2024 | SeverityMedium |
CVE-2023-51445GeoServer Stored Cross-Site Scripting (XSS) vulnerability in REST Resources API | Exploitation statusPublic exploit | FixNot confirmed | Published03/20/2024 | SeverityMedium |
CVE-2023-51444GeoServer arbitrary file upload vulnerability in REST Coverage Store API | Exploitation statusPublic exploit | FixNot confirmed | Published03/20/2024 | SeverityHigh |
CVE-2023-41877GeoServer log file path traversal vulnerability | Exploitation statusNot known exploited | FixNot confirmed | Published03/20/2024 | SeverityHigh |
CVE-2023-43795WPS Server Side Request Forgery in GeoServer | Exploitation statusNot known exploited | FixYes | Published10/24/2023 | SeverityHigh |
CVE-2023-41339Unsecured WMS dynamic styling sld=<url> parameter affords blind unauthenticated SSRF in GeoServer | Exploitation statusNot known exploited | FixYes | Published10/24/2023 | SeverityHigh |
CVE-2023-35042 | Exploitation statusNot known exploited | FixNot confirmed | Published06/12/2023 | SeverityUnknown |
CVE-2023-25157Unfiltered SQL Injection Vulnerabilities in Geoserver | Exploitation statusNot known exploited | FixNot confirmed | Published02/21/2023 | SeverityCritical |
CVE-2022-24847Improper Input Validation in GeoServer | Exploitation statusNot known exploited | FixNot confirmed | Published04/13/2022 | SeverityHigh |
CVE-2008-7227 | Exploitation statusNot confirmed | FixNot confirmed | Published09/14/2009 | SeverityUnknown |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan