Geoserver is a narrowly scoped geospatial mapping and data-serving platform that has achieved prominence in enterprise and open-source GIS deployments, creating a concentrated attack surface within its focused product line. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a strong, recurring tendency to acquire public exploit tooling and be confirmed as exploited in the wild. The exposure recurs across Geoserver and its associated GeoWebCache component through weakness classes including cross-site scripting, path traversal, improper input validation, and untrusted deserialization that reflect the platform's web-facing request handling and data-processing roles. Defenders should prioritize patching this vendor's releases and restrict network access to Geoserver instances; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Geoserver over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-36401CRITICAL GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2, multiple OGC request parameters allow | Jul 1, 2024 | 9.8 | 98 | YES | YES |
CVE-2025-58360CRITICAL GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2.26.2 and before 2.25.6, an XML External Entity (XXE) vulnera | Nov 25, 2025 | 9.8 | 97 | YES | YES |
CVE-2023-35042CRITICAL GeoServer 2, in some configurations, allows remote attackers to execute arbitrary code via java.lang.Runtime.getRuntime().exec in wps:LiteralData within a wps:Execute request, as e | Jun 12, 2023 | 9.8 | 53 | NO | NO |
CVE-2023-5786HIGH A vulnerability was found in GeoServer GeoWebCache up to 1.15.1. It has been declared as problematic. This vulnerability affects unknown code of the file /geoserver/gwc/rest.html. | Oct 26, 2023 | 8.8 | 25 | NO | NO |
CVE-2022-24846HIGH GeoWebCache is a tile caching server implemented in Java. The GeoWebCache disk quota mechanism can perform an unchecked JNDI lookup, which in turn can be used to perform class dese | Apr 14, 2022 | 7.2 | 25 | NO | NO |
CVE-2025-21621MEDIUM GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.25.0, a reflected cross-site scripting (XSS) vulnerability exists in the | Nov 25, 2025 | 6.1 | 22 | NO | NO |
CVE-2023-51444HIGH GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. An arbitrary file upload vulnerability exists in versions prior to | Mar 20, 2024 | 7.2 | 22 | NO | NO |
CVE-2024-24749HIGH GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.23.5 and 2.24.3, if GeoServer is deployed in the Windows operating syste | Jul 1, 2024 | 7.5 | 19 | NO | NO |
CVE-2023-41877HIGH GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A path traversal vulnerability in versions 2.23.4 and prior require | Mar 20, 2024 | 7.2 | 19 | NO | NO |
CVE-2024-23634MEDIUM GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. An arbitrary file renaming vulnerability exists in versions prior t | Mar 20, 2024 | 6.0 | 18 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Geoserver.
Media articles that mention a CVE ID that affects a product developed by Geoserver — matched by CVE ID, not by vendor name.