MapServer vulnerabilities
CVEs whose affected-version data names the MapServer package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-54355Medium· 5.3MapServer is a system for developing web-based GIS applications
MapServer is a system for developing web-based GIS applications. From 6.0 until 8.6.4, MapServer's OpenLayers HTML output for SERVICE=WMS&REQUEST=GetMap&FORMAT=application/openlayers reflects an attacker-controlled X-Forwarded-Host value…
▾ SunlitMapServer · MapServerEPSS 0.39%via NVD
CVE-2026-54354High· 8.2MapServer is a system for developing web-based GIS applications
MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS runtime filter translation in src/mappostgis.cpp and msPostGISLayerTranslateFilter() treats a filteritem as numeric when CONNECTIONTYPE …
▾ TwilightMapServer · MapServerEPSS 0.41%via NVD