All 4 CVE vulnerabilities found in core-geonetwork, with AI-generated Chinese analysis, references, and POCs.
Vendor: geonetwork
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-63219 | Unauthenticated file upload via missing authorization on formatter upload endpoint CWE-862 | 8.6 | High | 2026-09-03 |
| CVE-2026-58400 | GeoNetwork vulnerable to Remote Code Execution via unsafe Saxon XSLT processor configuration in formatter CWE-94 | 9.1 | Critical | 2026-09-03 |
| CVE-2026-53573 | core-geonetwork has an Open Redirect Bypass CWE-601 | 4.8 | Medium | 2026-07-31 |
| CVE-2024-32037 | GeoNetwork vulnerable to search end-point information disclosure in response headers CWE-200 | - | - | 2025-02-11 |
All 4 known CVE vulnerabilities affecting core-geonetwork with full Chinese analysis, references, and POCs where available.