Maven package intelligence

org.geoserver:gs-wms Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the Maven package org.geoserver:gs-wms, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
3
Known exploited vulnerabilities affecting org.geoserver:gs-wms
In CISA KEV
2
Records also listed in the official catalog
Beyond CISA KEV
1
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
0
org.geoserver:gs-wms KEVs with sensor-observed exploitation activity

Review org.geoserver:gs-wms exploitation against the versions you run

One of the three exploited org.geoserver:gs-wms vulnerabilities tracked here are not in CISA KEV.

67%
Covered by CISA
33%
Beyond CISA

Attested org.geoserver:gs-wms vulnerabilities

3 known exploited vulnerabilities affecting this package.

Vulnerability CISA KEV Added
CVE-2025-58360

GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature

In CISA 30 May 2026
CVE-2023-35042

GeoServer 2, in some configurations, allows remote attackers to execute arbitrary code via java.lang.Runtime.getRuntime().exec in wps:LiteralData...

Beyond CISA 12 Jun 2023
CVE-2024-36401

Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver

In CISA 15 Jul 2024

Recurring weakness patterns

Improper Restriction of XML External Entity Reference and Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') account for mapped occurrences across this org.geoserver:gs-wms KEV portfolio.

Browse all KEVs →