CVE Tools

Open-source-geospatial-foundation-osgeo

6 CVEs tracked since 2025. Since Jun 2025, none of them reached CISA KEV.

Open-source-geospatial-foundation-osgeo CVEs per month

Jun 2025 to Jun 2025. Point at a month, or focus the strip and use the arrow keys.
Open-source-geospatial-foundation-osgeo CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2025-0660

Products

The products that kept showing up in Open-source-geospatial-foundation-osgeo's monthly top three, with their CVEs summed over those months.

  1. Geoserver51 month
  2. Geotools21 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Open-source-geospatial-foundation-osgeo.

  1. CVE-2025-21621GeoServer Reflected Cross-Site Scripting (XSS) vulnerability in WMS GetFeatureInfo HTML format6.1
  2. CVE-2025-58360GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature8.2
  3. CVE-2025-59431MapServer - WFS XML Filter Query SQL injection9.8
  4. BDU:2025-06763Уязвимость модудей gt-xsd-core и gt-wfs-ng библиотеки GeoTools, позволяющая нарушителю проводить XXE-атаки9.9
  5. CVE-2025-30220GeoTools, GeoServer, and GeoNetwork XML External Entity (XXE) Processing Vulnerability in XSD schema handling9.9
  6. CVE-2024-40625GeoServer Coverage REST API Allows Server Side Request Forgery5.5
  7. CVE-2024-38524GWC Home Page communicate version and revision information5.3
  8. CVE-2024-34711GeoServer has improper ENTITY_RESOLUTION_ALLOWLIST URI validation in XML Processing (SSRF)9.3
  9. CVE-2024-29198GeoServer Vulnerable to Unauthenticated SSRF via TestWfsPost7.5
  10. BDU:2024-10977Уязвимость программного обеспечения для администрирования и публикации геоданных на сервере OSGeo GeoServer, существующая из-за непринятия мер по защите структуры веб-страницы, позволяющая нарушителю проводить межсайтовые сценарные атаки (XSS)6.5
  11. CVE-2024-36404GeoTools Remote Code Execution (RCE) vulnerability in evaluating XPath expressions9.8
  12. CVE-2024-36401Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver9.8
  13. CVE-2024-24749Classpath resource disclosure in GWC Web Resource API on Windows / Tomcat7.5
  14. CVE-2023-35042GeoServer 2, in some configurations, allows remote attackers to execute arbitrary code via java.lang.Runtime.getRuntime().exec in wps:LiteralData within a wps:Execute request, as exploited in the w...9.8
  15. CVE-2023-25157Unfiltered SQL Injection Vulnerabilities in Geoserver9.8

The record

Peak rank
#140 in Jun 2025
Busiest month shown
Jun 2025, 6 CVEs
Months with a KEV entry
0 since Jun 2025
Monthly snapshots
1 since 2025
Open-source-geospatial-foundation-osgeo's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store