Open-source-geospatial-foundation-osgeo
6 CVEs tracked since 2025. Since Jun 2025, none of them reached CISA KEV.
Open-source-geospatial-foundation-osgeo CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2025-06 | 6 | 0 |
Products
The products that kept showing up in Open-source-geospatial-foundation-osgeo's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Open-source-geospatial-foundation-osgeo.
- CVE-2025-21621GeoServer Reflected Cross-Site Scripting (XSS) vulnerability in WMS GetFeatureInfo HTML format6.1
- CVE-2025-58360GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature8.2
- CVE-2025-59431MapServer - WFS XML Filter Query SQL injection9.8
- BDU:2025-06763Уязвимость модудей gt-xsd-core и gt-wfs-ng библиотеки GeoTools, позволяющая нарушителю проводить XXE-атаки9.9
- CVE-2025-30220GeoTools, GeoServer, and GeoNetwork XML External Entity (XXE) Processing Vulnerability in XSD schema handling9.9
- CVE-2024-40625GeoServer Coverage REST API Allows Server Side Request Forgery5.5
- CVE-2024-38524GWC Home Page communicate version and revision information5.3
- CVE-2024-34711GeoServer has improper ENTITY_RESOLUTION_ALLOWLIST URI validation in XML Processing (SSRF)9.3
- CVE-2024-29198GeoServer Vulnerable to Unauthenticated SSRF via TestWfsPost7.5
- BDU:2024-10977Уязвимость программного обеспечения для администрирования и публикации геоданных на сервере OSGeo GeoServer, существующая из-за непринятия мер по защите структуры веб-страницы, позволяющая нарушителю проводить межсайтовые сценарные атаки (XSS)6.5
- CVE-2024-36404GeoTools Remote Code Execution (RCE) vulnerability in evaluating XPath expressions9.8
- CVE-2024-36401Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver9.8
- CVE-2024-24749Classpath resource disclosure in GWC Web Resource API on Windows / Tomcat7.5
- CVE-2023-35042GeoServer 2, in some configurations, allows remote attackers to execute arbitrary code via java.lang.Runtime.getRuntime().exec in wps:LiteralData within a wps:Execute request, as exploited in the w...9.8
- CVE-2023-25157Unfiltered SQL Injection Vulnerabilities in Geoserver9.8
The record
- Peak rank
- #140 in Jun 2025
- Busiest month shown
- Jun 2025, 6 CVEs
- Months with a KEV entry
- 0 since Jun 2025
- Monthly snapshots
- 1 since 2025