VendorsOSGeogeoserverall versions
Vulnerabilities

OSGeo GeoServer

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2025-30220
GeoTools, GeoServer, and GeoNetwork XML External Entity (XXE) Processing Vulnerability in XSD schema handling
Published 2025-06-10 · Analyzed
9.9EPSS 0.423
CVE-2023-25157
Unfiltered SQL Injection Vulnerabilities in Geoserver
Published 2023-02-21 · Modified
9.8EPSS 0.852
CVE-2023-43795
WPS Server Side Request Forgery in GeoServer
Published 2023-10-24 · Modified
9.8EPSS 0.677
CVE-2024-34711
GeoServer has improper ENTITY_RESOLUTION_ALLOWLIST URI validation in XML Processing (SSRF)
Published 2025-06-10 · Analyzed
9.3EPSS 0.003
CVE-2023-41339
Unsecured WMS dynamic styling sld=<url> parameter affords blind unauthenticated SSRF in GeoServer
Published 2023-10-24 · Modified
8.6EPSS 0.005
CVE-2024-29198
GeoServer Vulnerable to Unauthenticated SSRF via TestWfsPost
Published 2025-06-10 · Analyzed
8.2EPSS 0.023
CVE-2025-58175
GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity Resolution
Published 2026-06-18 · Analyzed
8.2EPSS 0.005
CVE-2021-40822
GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host.
Published 2022-05-01 · Modified
7.5EPSS 0.193
CVE-2025-30145
GeoServer has an Infinite Loop Vulnerability in Jiffle process
Published 2025-06-10 · Analyzed
7.5EPSS 0.005
CVE-2024-38524
GWC Home Page communicate version and revision information
Published 2025-06-10 · Analyzed
7.5EPSS 0.004
CVE-2022-24847
Improper Input Validation in GeoServer
Published 2022-04-13 · Modified
7.2EPSS 0.016
CVE-2025-27511
GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection
Published 2026-06-18 · Analyzed
7.2EPSS 0.011
CVE-2025-52465
GeoServer has an arbitrary file write vulnerability in its Master Password Dump Page
Published 2026-06-18 · Analyzed
7.2EPSS 0.006
CVE-2024-40625
GeoServer Coverage REST API Allows Server Side Request Forgery
Published 2025-06-10 · Analyzed
5.5EPSS 0.004
CVE-2025-27505
GeoServer Missing Authorization on REST API Index
Published 2025-06-10 · Analyzed
5.3EPSS 0.012
CVE-2024-35230
Welcome and About GeoServer pages communicate version and revision information
Published 2024-12-16 · Analyzed
5.3EPSS 0.007