VendorsEsriportal_for_arcgisall versions
Vulnerabilities

Esri Portal

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

88CVEs
CVE-2024-25693
Portal for ArcGIS has a directory traversal vulnerability.
Published 2024-04-04 · Analyzed
9.9EPSS 0.013
CVE-2026-13019
Missing Authentication
Published 2026-07-07 · Analyzed
9.8EPSS 0.007
CVE-2025-2538
BUG-000174336
Published 2025-03-20 · Modified
9.8EPSS 0.006
CVE-2026-33519
Incorrect privilege assignment in Portal for ArcGIS
Published 2026-04-21 · Analyzed
9.8EPSS 0.005
CVE-2026-13020
Weak Password Recovery Mechanism in Portal for ArcGIS
Published 2026-07-07 · Analyzed
9.8EPSS 0.005
CVE-2026-33518
Incorrect privilege assignment in Portal for ArcGIS
Published 2026-04-21 · Analyzed
9.8EPSS 0.005
CVE-2022-38193
Code injection issue in Portal for ArcGIS (10.7.1 and 10.8.1)
Published 2022-08-16 · Modified
9.6EPSS 0.009
CVE-2025-4967
Server Side Request Forgery (SSRF) vulnerability in Portal for ArcGIS
Published 2025-05-29 · Modified
9.1EPSS 0.005
CVE-2021-29108
There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below.
Published 2021-10-01 · Modified
8.8EPSS 0.008
CVE-2023-25832
BUG-000148346 There is a Cross-Site Request Forgery (CSRF) vulnerability in Portal for ArcGIS.
Published 2023-05-09 · Modified
8.8EPSS 0.003
CVE-2022-38205
Portal for ArcGIS has a directory traversal vulnerability (10.9.1, 10.8.1 and 10.7.1 only)
Published 2022-12-30 · Modified
8.6EPSS 0.015
CVE-2024-25699
Portal for ArcGIS has an invalid authentication vulnerability
Published 2024-04-04 · Analyzed
8.5EPSS 0.007
CVE-2023-25837
BUG-000133088 - ArcGIS Enterprise site builder is subject to stored XSS.
Published 2023-07-21 · Analyzed
8.4EPSS 0.010
CVE-2023-25835
BUG-000153659 ArcGIS Enterprise Sites has a stored XSS vulnerability
Published 2023-07-20 · Analyzed
8.4EPSS 0.009
CVE-2022-38184
There is an improper access control vulnerability in Portal for ArcGIS versions 10.8.1
Published 2022-08-16 · Modified
7.5EPSS 0.010
CVE-2022-38211
Server Side Request Forgery (SSRF) vulnerability in Portal for ArcGIS (10.9.1, 10.8.1 and 10.7.1 only)
Published 2022-12-30 · Modified
7.5EPSS 0.009
CVE-2022-38203
The allowedProxyHosts property is not fully honored in ArcGIS Enterprise (10.8.1 and 10.7.1 only)
Published 2022-12-30 · Modified
7.5EPSS 0.007
CVE-2022-38212
Server Side Request Forgery (SSRF) vulnerability in Portal for ArcGIS (10.8.1 and 10.7.1 only)
Published 2022-12-30 · Modified
7.5EPSS 0.007
CVE-2022-38187
Prevent access to sharing/rest/content/features/analyze to unauthorized users
Published 2022-08-15 · Modified
7.5EPSS 0.007
CVE-2024-38040
BUG-000167984 - Portal for ArcGIS has a Local file inclusion (LFI) vulnerability
Published 2024-10-04 · Modified
7.5EPSS 0.005
CVE-2026-69225
information disclosure vulnerability in Esri Portal for ArcGIS
Published 2026-08-21 · Analyzed
7.5EPSS 0.005
CVE-2026-69224
information disclosure vulnerability in Esri Portal for ArcGIS
Published 2026-08-21 · Analyzed
7.5EPSS 0.005
CVE-2024-25695
concatenated errors resulting in cross site scripting and frame injection issues.
Published 2024-04-04 · Modified
7.2EPSS 0.005
CVE-2022-38186
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below which may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the victim’s browser.
Published 2022-08-15 · Modified
7.1EPSS 0.006
CVE-2022-38188
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 which may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the victim’s browser.
Published 2022-08-15 · Modified
7.1EPSS 0.006
CVE-2022-38194
Portal for ArcGIS system properties are not properly encrypted (10.8.1 only)
Published 2022-08-16 · Modified
6.7EPSS 0.001
CVE-2021-29109
A reflected XSS vulnerability in Esri Portal for ArcGIS version 10.9.
Published 2021-10-01 · Modified
6.1EPSS 0.007
CVE-2022-38190
Stored cross-site scripting vulnerability in Esri Portal for ArcGIS Configurable Apps
Published 2022-08-15 · Modified
6.1EPSS 0.006
CVE-2022-38192
There is a stored cross-site scripting (XSS) vulnerability in ArcGIS API for JavaScript.
Published 2022-08-16 · Modified
6.1EPSS 0.006
CVE-2022-38191
HTML injection vulnerability in Portal for ArcGIS
Published 2022-08-15 · Modified
6.1EPSS 0.006
CVE-2023-25831
BUG-000154236 There is a reflected cross-site scripting (XSS) vulnerability in Portal for ArcGIS.
Published 2023-05-09 · Analyzed
6.1EPSS 0.005
CVE-2023-25830
BUG-000154662 Reflected XSS vulnerability in Portal for ArcGIS
Published 2023-05-09 · Analyzed
6.1EPSS 0.005
CVE-2022-38207
Reflected XSS vulnerability in Portal for ArcGIS (10.8.1 and 10.7.1 only)
Published 2022-12-30 · Modified
6.1EPSS 0.005
CVE-2022-38209
Reflected XSS vulnerability in Portal for ArcGIS
Published 2022-12-30 · Modified
6.1EPSS 0.005
CVE-2022-38210
HTML injection in accountswitcher-callback.html (10.9.1, 10.8.1 and 10.7.1 only)
Published 2022-12-30 · Modified
6.1EPSS 0.005
CVE-2022-38204
Reflected XSS vulnerability in Portal for ArcGIS (10.8.1 and 10.7.1 only)
Published 2022-12-30 · Modified
6.1EPSS 0.005
CVE-2022-38206
Reflected XSS vulnerability in Portal for ArcGIS (10.9.1, 10.8.1 and 10.7.1 only)
Published 2022-12-30 · Modified
6.1EPSS 0.005
CVE-2023-25829
BUG-000155001 - Unvalidated redirect in Portal for ArcGIS.
Published 2023-05-09 · Analyzed
6.1EPSS 0.005
CVE-2022-38208
Unvalidated redirect in Portal for ArcGIS
Published 2022-12-30 · Modified
6.1EPSS 0.005
CVE-2024-25709
Self-XSS style in move item dialog
Published 2024-04-04 · Analyzed
6.1EPSS 0.004
1 / 3Next →