VYPR
Vendor

Geoserver

Products
2
CVEs
35
Across products
35
Status
Private

Products

2

Recent CVEs

35
View all 35 CVEs →
  • CVE-2024-36401CriKEVJul 1, 2024
    risk 0.80cvss 9.8epss 1.00

    GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2, multiple OGC request parameters allow Remote Code Execution (RCE) by unauthenticated users through specially crafted input against a…

  • CVE-2025-58360HigKEVNov 25, 2025
    risk 0.74cvss 8.2epss 0.65

    GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2.26.2 and before 2.25.6, an XML External Entity (XXE) vulnerability was identified. The application accepts XML input through a specific endpoint /geoserver/wms…

  • CVE-2023-35042CriJun 12, 2023
    risk 0.67cvss 9.8epss 0.43

    GeoServer 2, in some configurations, allows remote attackers to execute arbitrary code via java.lang.Runtime.getRuntime().exec in wps:LiteralData within a wps:Execute request, as exploited in the wild in June 2023. NOTE: the vendor states that they are unable to reproduce this…

  • CVE-2023-25157CriFeb 21, 2023
    risk 0.64cvss 9.8epss 0.85

    GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. GeoServer includes support for the OGC Filter expression language and the OGC Common Query Language (CQL) as part of the Web Feature Service (WFS) and Web Map Service…

  • CVE-2025-30220CriJun 10, 2025
    risk 0.61cvss 9.9epss 0.57

    GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent schema data structure is vulnerable to XML External Entity (XXE) exploit. This impacts whoever exposes XML processing with…

  • CVE-2023-43795HigOct 25, 2023
    risk 0.61cvss 8.6epss 0.68

    GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The OGC Web Processing Service (WPS) specification is designed to process information from any server using GET and POST requests. This presents the opportunity for…

  • CVE-2024-34711CriJun 10, 2025
    risk 0.60cvss 9.3epss 0.00

    GeoServer is an open source server that allows users to share and edit geospatial data. An improper URI validation vulnerability exists that enables an unauthorized attacker to perform XML External Entities (XEE) attack, then send GET request to any HTTP server. By default,…

  • CVE-2022-24846CriApr 14, 2022
    risk 0.59cvss 9.1epss 0.01

    GeoWebCache is a tile caching server implemented in Java. The GeoWebCache disk quota mechanism can perform an unchecked JNDI lookup, which in turn can be used to perform class deserialization and result in arbitrary code execution. While in GeoWebCache the JNDI strings are…

  • CVE-2021-40822HigMay 2, 2022
    risk 0.50cvss 7.5epss 0.19

    GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host.

  • CVE-2024-29198HigJun 10, 2025
    risk 0.49cvss 7.5epss 0.02

    GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. It possible to achieve Service Side Request Forgery (SSRF) via the Demo request endpoint if Proxy Base URL has not been set. Upgrading to GeoServer 2.24.4, or 2.25.2,…

  • CVE-2023-41339HigOct 25, 2023
    risk 0.49cvss 8.6epss 0.01

    GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The WMS specification defines an ``sld=`` parameter for GetMap, GetLegendGraphic and GetFeatureInfo operations for user supplied "dynamic styling". Enabling the…

  • CVE-2023-41877HigMar 20, 2024
    risk 0.47cvss 7.2epss 0.01

    GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A path traversal vulnerability in versions 2.23.4 and prior requires GeoServer Administrator with access to the admin console to misconfigure the Global Settings for…

  • CVE-2025-30145HigJun 10, 2025
    risk 0.42cvss 7.5epss 0.00

    GeoServer is an open source server that allows users to share and edit geospatial data. Malicious Jiffle scripts can be executed by GeoServer, either as a rendering transformation in WMS dynamic styles or as a WPS process, that can enter an infinite loop to trigger denial of…

  • CVE-2024-24749HigJul 1, 2024
    risk 0.42cvss 7.5epss 0.01

    GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.23.5 and 2.24.3, if GeoServer is deployed in the Windows operating system using an Apache Tomcat web application server, it is possible to bypass existing input validation…

  • CVE-2025-52465HigJun 18, 2026
    risk 0.40cvss 7.2epss 0.01

    GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.27.3, a vulnerability exists that allows an authenticated administrator with access to GeoServer's security system to pass arbitrary file names to the Master…

  • CVE-2023-51444HigMar 20, 2024
    risk 0.40cvss 7.2epss 0.02

    GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. An arbitrary file upload vulnerability exists in versions prior to 2.23.4 and 2.24.1 that enables an authenticated administrator with permissions to modify coverage…

  • CVE-2022-24847HigApr 13, 2022
    risk 0.40cvss 7.2epss 0.01

    GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The GeoServer security mechanism can perform an unchecked JNDI lookup, which in turn can be used to perform class deserialization and result in arbitrary code…

  • CVE-2025-27511HigJun 18, 2026
    risk 0.39cvss 7.2epss 0.01

    GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE).…

  • CVE-2025-58175MedJun 18, 2026
    risk 0.35cvss 6.5epss 0.00

    GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.27.3, a GeoServer that uses `ENTITY_RESOLUTION_ALLOWLIST` may allow attacker to perform unauthenticated Server-Side Request Forgery (SSRF). This vulnerability…

  • CVE-2023-5786MedOct 26, 2023
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was found in GeoServer GeoWebCache up to 1.15.1. It has been declared as problematic. This vulnerability affects unknown code of the file /geoserver/gwc/rest.html. The manipulation leads to direct request. The attack can be initiated remotely. The exploit has…