📦 Geoserver

by Geoserver

🔍 What is Geoserver?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-36401

CRITICAL CVSS 9.8 Jul 1, 2024

This vulnerability allows unauthenticated remote attackers to execute arbitrary code on GeoServer instances by sending specially crafted OGC requests. It affects ALL default GeoServer installations du...

CVE-2024-24749

HIGH CVSS 7.5 Jul 1, 2024

This vulnerability in GeoServer allows attackers to bypass input validation and read arbitrary classpath resources with specific file extensions when deployed on Windows with Apache Tomcat. If using a...

CVE-2023-41877

HIGH CVSS 7.2 Mar 20, 2024

This CVE describes a path traversal vulnerability in GeoServer that allows administrators with access to the admin console to misconfigure log file locations to arbitrary paths, then view the contents...

CVE-2025-21621

MEDIUM CVSS 6.1 Nov 25, 2025

GeoServer versions before 2.25.0 contain a reflected cross-site scripting vulnerability in the WMS GetFeatureInfo HTML output format. Attackers can inject malicious JavaScript via SLD_BODY parameters,...

CVE-2024-34696

MEDIUM CVSS 4.5 Jul 1, 2024

GeoServer versions 2.10.0 through 2.24.3 and 2.25.0 expose environment variables and Java properties containing sensitive credentials to authenticated administrators via the Server Status page and RES...