VDB
GCVE-110-NCSC-2026-343
GCVE-110-NCSC-2026-343
Advisory PublishedCVSS 8.6/10
GeoNetwork versions 4.4.5 through 4.4.11 contain a reflected cross-site scripting (XSS) vulnerability in the public unauthenticated catalog search due to improper sanitization of the uiconfig query parameter, enabling arbitrary JavaScript execution.
Weaknesses (CWE)
CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-470Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')CWE-862Missing Authorization
Risk Scores
CVSS 3.1
8.6/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| geonetwork | vers:unknown/* | — | — |
| Open Source | vers:unknown/* | — | — |
Aliases
Browse GCVE Records
1,280 records in the GCVE database · Updated September 7, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.