Maven package intelligence

org.geoserver.web:gs-web-app Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the Maven package org.geoserver.web:gs-web-app, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
4
Known exploited vulnerabilities affecting org.geoserver.web:gs-web-app
In CISA KEV
2
Records also listed in the official catalog
Beyond CISA KEV
2
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
0
org.geoserver.web:gs-web-app KEVs with sensor-observed exploitation activity

Review org.geoserver.web:gs-web-app exploitation against the versions you run

Two of the four exploited org.geoserver.web:gs-web-app vulnerabilities tracked here are not in CISA KEV.

50%
Covered by CISA
50%
Beyond CISA

Attested org.geoserver.web:gs-web-app vulnerabilities

4 known exploited vulnerabilities affecting this package.

Vulnerability CISA KEV Added
CVE-2025-27505

GeoServer Missing Authorization on REST API Index

Beyond CISA 20 Nov 2025
CVE-2025-30220

GeoTools, GeoServer, and GeoNetwork XML External Entity (XXE) Processing Vulnerability in XSD schema handling

Beyond CISA 02 Aug 2025
CVE-2025-58360

GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature

In CISA 30 May 2026
CVE-2024-36401

Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver

In CISA 15 Jul 2024

Recurring weakness patterns

Improper Restriction of XML External Entity Reference, Missing Authorization, and Server-Side Request Forgery (SSRF) account for mapped occurrences across this org.geoserver.web:gs-web-app KEV portfolio.

Browse all KEVs →