Known CVE
GeoServer WFS - XXE Processing Vulnerability
GeoServer Web Feature Service (WFS) is vulnerable to an XML External Entity (XXE) processing attack due to improper handling of XML input. This vulnerability allows attackers to perform Out-of-Band (OOB) data exfiltration and Server-Side Request Forgery (SSRF) by exploiting the GeoTools library.
CVE-2025-30220
Critical2025CVSS 9.9CWE-611
cve2025 · geoserver · xxe · oast · oob · ssrf · unauth · vkev
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website