Geosolutionsgroup develops a narrowly scoped portfolio of geospatial and imaging software, with GeoNode and JAI-Ext forming the core exposure; despite limited product breadth, these tools occupy a prominent niche in open-source geospatial infrastructure. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, demonstrate an elevated tendency toward confirmed in-the-wild exploitation, and frequently acquire public exploit code, reflecting the web-facing and data-handling attack surface inherent to mapping and imagery platforms. The exposure recurs through high-impact weakness classes including server-side request forgery, sensitive information disclosure, code injection, cross-site scripting, and improper XML entity handling—classes that affect both authentication and data integrity in systems processing untrusted geographic data and user input. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Geosolutionsgroup over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24816CRITICAL JAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing Jiffle script to be provided via network request can lead to a Remote | Apr 13, 2022 | 10.0 | 98 | YES | YES |
CVE-2026-39922MEDIUM GeoNode versions 4.4.5 and 5.0.2 (and prior within their respective releases) contain a server-side request forgery vulnerability in the service registration endpoint that allows a | Apr 10, 2026 | 6.3 | 25 | NO | NO |
CVE-2026-39921MEDIUM GeoNode versions 4.0 before 4.4.5 and 5.0 before 5.0.2 contain a server-side request forgery vulnerability that allows authenticated users with document upload permissions to trigg | Apr 10, 2026 | 6.3 | 25 | NO | NO |
CVE-2023-40017HIGH GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. In versions 3.2.0 through 4.1.2, the endpoint `/proxy/?url=` do | Aug 24, 2023 | 7.5 | 21 | NO | NO |
CVE-2023-26043MEDIUM GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. GeoNode is vulnerable to an XML External Entity (XXE) injection | Feb 27, 2023 | 6.5 | 21 | NO | NO |
CVE-2023-42439MEDIUM GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. A SSRF vulnerability exists starting in version 3.2.0, bypassin | Sep 15, 2023 | 6.5 | 20 | NO | NO |
CVE-2024-27091MEDIUM GeoNode is a geospatial content management system, a platform for the management and publication of geospatial data. An issue exists within GEONODE where the current rich text edit | Mar 27, 2024 | 6.1 | 19 | NO | NO |
CVE-2023-28442MEDIUM GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. Prior to versions 2.20.6, 2.19.6, and 2.18.7, anonymous users c | Mar 24, 2023 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Geosolutionsgroup.
Media articles that mention a CVE ID that affects a product developed by Geosolutionsgroup — matched by CVE ID, not by vendor name.