Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Geosolutionsgroup

First CVE: Apr 13, 2022Active for: 4 yearsTotal CVEs: 8

Geosolutionsgroup develops a narrowly scoped portfolio of geospatial and imaging software, with GeoNode and JAI-Ext forming the core exposure; despite limited product breadth, these tools occupy a prominent niche in open-source geospatial infrastructure. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, demonstrate an elevated tendency toward confirmed in-the-wild exploitation, and frequently acquire public exploit code, reflecting the web-facing and data-handling attack surface inherent to mapping and imagery platforms. The exposure recurs through high-impact weakness classes including server-side request forgery, sensitive information disclosure, code injection, cross-site scripting, and improper XML entity handling—classes that affect both authentication and data integrity in systems processing untrusted geographic data and user input. Live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 47% of tracked vendors
12.5%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Geosolutionsgroup over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 13, 2022
4 years ago
Most Recent CVE
Apr 10, 2026
105 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-24816CRITICAL
JAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing Jiffle script to be provided via network request can lead to a Remote
Apr 13, 202210.098YESYES
CVE-2026-39922MEDIUM
GeoNode versions 4.4.5 and 5.0.2 (and prior within their respective releases) contain a server-side request forgery vulnerability in the service registration endpoint that allows a
Apr 10, 20266.325NONO
CVE-2026-39921MEDIUM
GeoNode versions 4.0 before 4.4.5 and 5.0 before 5.0.2 contain a server-side request forgery vulnerability that allows authenticated users with document upload permissions to trigg
Apr 10, 20266.325NONO
CVE-2023-40017HIGH
GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. In versions 3.2.0 through 4.1.2, the endpoint `/proxy/?url=` do
Aug 24, 20237.521NONO
CVE-2023-26043MEDIUM
GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. GeoNode is vulnerable to an XML External Entity (XXE) injection
Feb 27, 20236.521NONO
CVE-2023-42439MEDIUM
GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. A SSRF vulnerability exists starting in version 3.2.0, bypassin
Sep 15, 20236.520NONO
CVE-2024-27091MEDIUM
GeoNode is a geospatial content management system, a platform for the management and publication of geospatial data. An issue exists within GEONODE where the current rich text edit
Mar 27, 20246.119NONO
CVE-2023-28442MEDIUM
GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. Prior to versions 2.20.6, 2.19.6, and 2.18.7, anonymous users c
Mar 24, 20235.319NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
75%
13%
13%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (87.5%)
Unknown0 (0.0%)
Required1 (12.5%)
Privileges Required
Low4 (50.0%)
High0 (0.0%)
None4 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
1 CVE
12.5% of CVEs· 100th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
12.5% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Geosolutionsgroup.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Geosolutionsgroup — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Geosolutionsgroup's Products

View all 2 CNAs →

Top CWEs