SecAlerts
g

geoserver

Security Risk Profile

67
/100
high

Security Risk Score

Comprehensive risk assessment based on 22 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from September 14, 2009 to present

22
Total CVEs
8
Critical+High
4
Exploited
3
Unpatched

Threat Assessment

Avg CVSS
6.6
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
3
Critical/High
Risk Level
67/100
high
⚠️ 4 Active Exploits 1 Zero-Days

Severity Distribution

Critical
4
High
4
Medium
11
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
1

Age Distribution

Common Weaknesses (CWE)

1
XSS
9
2
Input Validation
4
3
Path Traversal
3
4
Code Injection
2
5
XEE
1

Most Affected Products

1. GeoServer geoserver59
2. maven/org.geoserver:gs-wms14
3. maven/org.geoserver.web:gs-web-app12
4. maven/org.geoserver:gs-wfs7
5. GeoTools GeoTools7

Recent Vulnerabilities

See more →
https://reddit.com/r/netsec/comments/1ufdc3k/cve202552465_geoserver_arbitrary_file_write/
unknown

CVE-2025-52465 geoserver arbitrary file write vulnerability

Jun 25, 2026🔧 No Patch
https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-geoserver-flaw/
unknown

CISA orders feds to patch actively exploited Geoserver flaw

Dec 12, 2025⚠ Exploited🔧 No Patch
CVE-2025-58360
CVSS 9.8critical

OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability

Nov 25, 2025⚠ Exploited
CVE-2025-21621
CVSS 6.1medium

GeoServer Reflected Cross-Site Scripting (XSS) vulnerability in WMS GetFeatureInfo HTML format

Nov 25, 2025
https://www.bleepingcomputer.com/news/security/cisa-says-hackers-breached-federal-agency-using-geoserver-exploit/
unknown

CISA says hackers breached federal agency using GeoServer exploit

Sep 23, 2025⚠ Exploited⚡ Zero-Day🔧 No Patch
CVE-2024-36401
CVSS 9.8critical

Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver

Jul 1, 2024⚠ Exploited
CVE-2024-34696
CVSS 4.9medium

GeoServer's Server Status shows sensitive environmental variables and Java properties

Jul 1, 2024
CVE-2024-24749
CVSS 7.5high

Classpath resource disclosure in GWC Web Resource API on Windows / Tomcat

Jul 1, 2024
CVE-2024-23821
CVSS 4.8medium

GeoServer's GWC Demos Page vulnerable to Stored Cross-Site Scripting (XSS)

Mar 20, 2024
CVE-2024-23819
CVSS 4.8medium

GeoServer Stored Cross-Site Scripting (XSS) vulnerability in MapML HTML Page

Mar 20, 2024

Monitor geoserver in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

geoserver Security Vulnerabilities & Risk Score | 22 CVEs | SecAlerts - SecAlerts