CVE-2025-21621 is a reflected cross-site scripting (XSS) vulnerability in GeoServer versions prior to 2.25.0, allowing remote attackers to execute arbitrary JavaScript in a user's browser via crafted SLD_BODY parameters in the WMS GetFeatureInfo HTML output. This medium-severity vulnerability (CVSS 6.1) requires user interaction and has a low impact on confidentiality and integrity. While there are no public exploit modules like Metasploit or Nuclei, and it's not in CISA's KEV catalog, there is one reported instance of active exploitation in the wild and limited community discussion, indicating some real-world relevance despite the lack of widespread public exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.25.0CPE matchmatch criteria | cpe:2.3:a:geoserver:geoserver:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.