geonetwork-opensource has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was July 2026 with 3. The median CVSS is 7.3 (high).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.3
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Weakness classes
Products
- org.geonetwork-opensource:geonetwork 3
3
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-46487High· 7.5GeoNetwork has ACL bypass on Elasticsearch search when request body omits query field41CVE-2026-39379High· 7.1GeoNetwork has reflected XSS through client-side template injection39CVE-2026-53573MediumGeoNetwork is a catalog application to manage spatially referenced resources28
geonetwork-opensource vulnerabilities
CVEs affecting geonetwork-opensource, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-53573MediumGeoNetwork is a catalog application to manage spatially referenced resources
GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter permits…
▾ Sunlitgeonetwork-opensource · org.geonetwork-opensource:geonetworkEPSS 0.38%via NVD
CVE-2026-39379High· 7.1GeoNetwork has reflected XSS through client-side template injection
GeoNetwork has reflected XSS through client-side template injection
▾ Twilightgeonetwork-opensource · org.geonetwork-opensource:geonetworkvia GHSA
CVE-2026-46487High· 7.5GeoNetwork has ACL bypass on Elasticsearch search when request body omits query field
GeoNetwork has ACL bypass on Elasticsearch search when request body omits query field
▾ Twilightgeonetwork-opensource · org.geonetwork-opensource:geonetworkvia GHSA