Known vulnerabilities in geoserver geoserver 2.24.1

Vendor: geoserver
Website: https://github.com/geoserver
Total Security Bulletins: 5

Security bulletins (5)

Secuity bulletin Severity Status Published
SB2025112608: XML External Entity injection in GeoServer High
Patched Exploited
26.11.2025
SB2025112607: Reflected cross-site scripting in GeoServer Low
Patched
26.11.2025
SB2024121929: Information disclosure in GeoServer Low
Patched
19.12.2024
SB2024103051: Security restrictions bypass in GeoServer Medium
Patched
30.10.2024
SB2024071555: Remote code execution in GeoServer Critical
Patched Exploited
15.07.2024