Browse all 5 CVE security advisories affecting geonetwork. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-63219 | Unauthenticated file upload via missing authorization on formatter upload endpoint — core-geonetwork CWE-862 | 8.6 | High | 2026-09-03 |
| CVE-2026-58400 | GeoNetwork vulnerable to Remote Code Execution via unsafe Saxon XSLT processor configuration in formatter — core-geonetwork CWE-94 | 9.1 | Critical | 2026-09-03 |
| CVE-2026-53573 | core-geonetwork has an Open Redirect Bypass — core-geonetwork CWE-601 | 4.8 | Medium | 2026-07-31 |
| CVE-2022-50899 | Geonetwork 4.2.0 - XML External Entity (XXE) — GeoNetwork CWE-611 | 6.5 | Medium | 2026-01-13 |
| CVE-2024-32037 | GeoNetwork vulnerable to search end-point information disclosure in response headers — core-geonetwork CWE-200 | - | - | 2025-02-11 |
This page lists every published CVE security advisory associated with geonetwork. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.