VendorsEsriportal_for_arcgisany version
Vulnerabilities

Esri Portal any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

61CVEs
CVE-2024-25693
Portal for ArcGIS has a directory traversal vulnerability.
Published 2024-04-04 · Analyzed
9.9EPSS 0.013
CVE-2026-13019
Missing Authentication
Published 2026-07-07 · Analyzed
9.8EPSS 0.007
CVE-2025-2538
BUG-000174336
Published 2025-03-20 · Modified
9.8EPSS 0.006
CVE-2026-13020
Weak Password Recovery Mechanism in Portal for ArcGIS
Published 2026-07-07 · Analyzed
9.8EPSS 0.005
CVE-2022-38193
Code injection issue in Portal for ArcGIS (10.7.1 and 10.8.1)
Published 2022-08-16 · Modified
9.6EPSS 0.009
CVE-2025-4967
Server Side Request Forgery (SSRF) vulnerability in Portal for ArcGIS
Published 2025-05-29 · Modified
9.1EPSS 0.005
CVE-2021-29108
There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below.
Published 2021-10-01 · Modified
8.8EPSS 0.008
CVE-2023-25832
BUG-000148346 There is a Cross-Site Request Forgery (CSRF) vulnerability in Portal for ArcGIS.
Published 2023-05-09 · Modified
8.8EPSS 0.003
CVE-2022-38205
Portal for ArcGIS has a directory traversal vulnerability (10.9.1, 10.8.1 and 10.7.1 only)
Published 2022-12-30 · Modified
8.6EPSS 0.015
CVE-2024-25699
Portal for ArcGIS has an invalid authentication vulnerability
Published 2024-04-04 · Analyzed
8.5EPSS 0.007
CVE-2023-25837
BUG-000133088 - ArcGIS Enterprise site builder is subject to stored XSS.
Published 2023-07-21 · Analyzed
8.4EPSS 0.010
CVE-2023-25835
BUG-000153659 ArcGIS Enterprise Sites has a stored XSS vulnerability
Published 2023-07-20 · Analyzed
8.4EPSS 0.009
CVE-2022-38184
There is an improper access control vulnerability in Portal for ArcGIS versions 10.8.1
Published 2022-08-16 · Modified
7.5EPSS 0.010
CVE-2022-38211
Server Side Request Forgery (SSRF) vulnerability in Portal for ArcGIS (10.9.1, 10.8.1 and 10.7.1 only)
Published 2022-12-30 · Modified
7.5EPSS 0.009
CVE-2022-38212
Server Side Request Forgery (SSRF) vulnerability in Portal for ArcGIS (10.8.1 and 10.7.1 only)
Published 2022-12-30 · Modified
7.5EPSS 0.007
CVE-2022-38203
The allowedProxyHosts property is not fully honored in ArcGIS Enterprise (10.8.1 and 10.7.1 only)
Published 2022-12-30 · Modified
7.5EPSS 0.007
CVE-2022-38187
Prevent access to sharing/rest/content/features/analyze to unauthorized users
Published 2022-08-15 · Modified
7.5EPSS 0.007
CVE-2026-69224
information disclosure vulnerability in Esri Portal for ArcGIS
Published 2026-08-21 · Analyzed
7.5EPSS 0.005
CVE-2024-25695
concatenated errors resulting in cross site scripting and frame injection issues.
Published 2024-04-04 · Modified
7.2EPSS 0.005
CVE-2022-38186
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below which may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the victim’s browser.
Published 2022-08-15 · Modified
7.1EPSS 0.006
CVE-2022-38188
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 which may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the victim’s browser.
Published 2022-08-15 · Modified
7.1EPSS 0.006
CVE-2021-29109
A reflected XSS vulnerability in Esri Portal for ArcGIS version 10.9.
Published 2021-10-01 · Modified
6.1EPSS 0.007
CVE-2022-38190
Stored cross-site scripting vulnerability in Esri Portal for ArcGIS Configurable Apps
Published 2022-08-15 · Modified
6.1EPSS 0.006
CVE-2022-38192
There is a stored cross-site scripting (XSS) vulnerability in ArcGIS API for JavaScript.
Published 2022-08-16 · Modified
6.1EPSS 0.006
CVE-2022-38191
HTML injection vulnerability in Portal for ArcGIS
Published 2022-08-15 · Modified
6.1EPSS 0.006
CVE-2022-38209
Reflected XSS vulnerability in Portal for ArcGIS
Published 2022-12-30 · Modified
6.1EPSS 0.005
CVE-2022-38210
HTML injection in accountswitcher-callback.html (10.9.1, 10.8.1 and 10.7.1 only)
Published 2022-12-30 · Modified
6.1EPSS 0.005
CVE-2022-38206
Reflected XSS vulnerability in Portal for ArcGIS (10.9.1, 10.8.1 and 10.7.1 only)
Published 2022-12-30 · Modified
6.1EPSS 0.005
CVE-2022-38208
Unvalidated redirect in Portal for ArcGIS
Published 2022-12-30 · Modified
6.1EPSS 0.005
CVE-2024-25698
Reflected XSS in Portal for ArcGIS
Published 2024-04-04 · Analyzed
6.1EPSS 0.004
CVE-2024-25706
HTMLi at createFolder Content Injection
Published 2024-04-04 · Modified
6.1EPSS 0.004
CVE-2026-69234
reflected cross site scripting vulnerability in Esri Portal for ArcGIS
Published 2026-08-21 · Analyzed
6.1EPSS 0.003
CVE-2026-69235
stored cross site scripting issue in Esri Portal for ArcGIS
Published 2026-08-21 · Analyzed
6.1EPSS 0.003
CVE-2026-69236
stored cross site scripting issue in Esri Portal for ArcGIS
Published 2026-08-21 · Analyzed
6.1EPSS 0.003
CVE-2026-69232
stored cross site scripting issue in Esri Portal for ArcGIS
Published 2026-08-21 · Analyzed
5.5EPSS 0.003
CVE-2026-69231
stored cross site scripting issue in Esri Portal for ArcGIS
Published 2026-08-21 · Analyzed
5.5EPSS 0.003
CVE-2026-69233
stored cross site scripting issue in Esri Portal for ArcGIS
Published 2026-08-21 · Analyzed
5.5EPSS 0.003
CVE-2026-69230
stored cross site scripting issue in Esri Portal for ArcGIS
Published 2026-08-21 · Analyzed
5.5EPSS 0.002
CVE-2021-29110
Stored cross-site scripting (XSS) issue in Esri Portal for ArcGIS may allow a remote unauthenticated attacker to pass and store malicious strings in the home application.
Published 2021-10-01 · Modified
5.4EPSS 0.007
CVE-2022-38189
There is a stored cross-site scripting (XSS) vulnerability in ArcGIS API for JavaScript.
Published 2022-08-16 · Modified
5.4EPSS 0.006
1 / 2Next →