Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Geoserver

First CVE: Sep 14, 2009Active for: 17 yearsTotal CVEs: 19
63.7
VTI Score
TOP TARGET

Geoserver is a narrowly scoped geospatial mapping and data-serving platform that has achieved prominence in enterprise and open-source GIS deployments, creating a concentrated attack surface within its focused product line. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a strong, recurring tendency to acquire public exploit tooling and be confirmed as exploited in the wild. The exposure recurs across Geoserver and its associated GeoWebCache component through weakness classes including cross-site scripting, path traversal, improper input validation, and untrusted deserialization that reflect the platform's web-facing request handling and data-processing roles. Defenders should prioritize patching this vendor's releases and restrict network access to Geoserver instances; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
19
Total CVEs
More Total CVEs than 96% of tracked vendors
1.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
10.5%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Geoserver over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 14, 2009
16 years ago
Most Recent CVE
Nov 25, 2025
242 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-36401CRITICAL
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2, multiple OGC request parameters allow
Jul 1, 20249.898YESYES
CVE-2025-58360CRITICAL
GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2.26.2 and before 2.25.6, an XML External Entity (XXE) vulnera
Nov 25, 20259.897YESYES
CVE-2023-35042CRITICAL
GeoServer 2, in some configurations, allows remote attackers to execute arbitrary code via java.lang.Runtime.getRuntime().exec in wps:LiteralData within a wps:Execute request, as e
Jun 12, 20239.853NONO
CVE-2023-5786HIGH
A vulnerability was found in GeoServer GeoWebCache up to 1.15.1. It has been declared as problematic. This vulnerability affects unknown code of the file /geoserver/gwc/rest.html.
Oct 26, 20238.825NONO
CVE-2022-24846HIGH
GeoWebCache is a tile caching server implemented in Java. The GeoWebCache disk quota mechanism can perform an unchecked JNDI lookup, which in turn can be used to perform class dese
Apr 14, 20227.225NONO
CVE-2025-21621MEDIUM
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.25.0, a reflected cross-site scripting (XSS) vulnerability exists in the
Nov 25, 20256.122NONO
CVE-2023-51444HIGH
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. An arbitrary file upload vulnerability exists in versions prior to
Mar 20, 20247.222NONO
CVE-2024-24749HIGH
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.23.5 and 2.24.3, if GeoServer is deployed in the Windows operating syste
Jul 1, 20247.519NONO
CVE-2023-41877HIGH
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A path traversal vulnerability in versions 2.23.4 and prior require
Mar 20, 20247.219NONO
CVE-2024-23634MEDIUM
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. An arbitrary file renaming vulnerability exists in versions prior t
Mar 20, 20246.018NONO
View all 19 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products19 CVEs
58%
26%
16%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network18 (94.7%)
Unknown1 (5.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (94.7%)
High0 (0.0%)
Unknown1 (5.3%)
User Interaction
None10 (52.6%)
Unknown1 (5.3%)
Required8 (42.1%)
Privileges Required
Low1 (5.3%)
High12 (63.2%)
None5 (26.3%)
Unknown1 (5.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (19 CVEs).

CISA KEV
2 CVEs
10.5% of CVEs· 100th percentile
Metasploit
2 CVEs
10.5% of CVEs· 98th percentile
Nuclei
2 CVEs
10.5% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Geoserver.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Geoserver — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Geoserver's Products

View all 3 CNAs →

Top CWEs