VendorsEsriportal_for_arcgisall versions
Vulnerabilities

Esri Portal

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

88CVEs
CVE-2024-25706
HTMLi at createFolder Content Injection
Published 2024-04-04 · Modified
6.1EPSS 0.004
CVE-2024-25698
Reflected XSS in Portal for ArcGIS
Published 2024-04-04 · Analyzed
6.1EPSS 0.004
CVE-2024-38038
BUG-000165732 - Reflected XSS in Portal for ArcGIS
Published 2024-10-04 · Modified
6.1EPSS 0.003
CVE-2024-25691
BUG-000165286 - Reflected XSS in Portal for ArcGIS
Published 2024-10-04 · Modified
6.1EPSS 0.003
CVE-2026-69234
reflected cross site scripting vulnerability in Esri Portal for ArcGIS
Published 2026-08-21 · Analyzed
6.1EPSS 0.003
CVE-2024-8148
BUG-000168624 - Unvalidated redirect in Portal for ArcGIS. (11.2, 11.1, 10.9.1. and 10.8.1)
Published 2024-10-04 · Modified
6.1EPSS 0.003
CVE-2024-38037
BUG-000167983 - Unvalidated redirect in Portal for ArcGIS
Published 2024-10-04 · Modified
6.1EPSS 0.003
CVE-2026-69235
stored cross site scripting issue in Esri Portal for ArcGIS
Published 2026-08-21 · Analyzed
6.1EPSS 0.003
CVE-2026-69236
stored cross site scripting issue in Esri Portal for ArcGIS
Published 2026-08-21 · Analyzed
6.1EPSS 0.003
CVE-2025-57872
BUG-000174150 - Unvalidated redirect in Portal for ArcGIS.
Published 2025-09-29 · Analyzed
6.1EPSS 0.002
CVE-2025-57878
BUG-000174149 - The Portal for ArcGIS has an unvalidated redirect.
Published 2025-09-29 · Analyzed
6.1EPSS 0.002
CVE-2025-57879
BUG-000171009 - URL manipulation vulnerability in Portal for ArcGIS.
Published 2025-09-29 · Analyzed
6.1EPSS 0.002
CVE-2026-69231
stored cross site scripting issue in Esri Portal for ArcGIS
Published 2026-08-21 · Analyzed
5.5EPSS 0.003
CVE-2026-69232
stored cross site scripting issue in Esri Portal for ArcGIS
Published 2026-08-21 · Analyzed
5.5EPSS 0.003
CVE-2026-69233
stored cross site scripting issue in Esri Portal for ArcGIS
Published 2026-08-21 · Analyzed
5.5EPSS 0.003
CVE-2026-69230
stored cross site scripting issue in Esri Portal for ArcGIS
Published 2026-08-21 · Analyzed
5.5EPSS 0.002
CVE-2021-29110
Stored cross-site scripting (XSS) issue in Esri Portal for ArcGIS may allow a remote unauthenticated attacker to pass and store malicious strings in the home application.
Published 2021-10-01 · Modified
5.4EPSS 0.007
CVE-2024-38036
BUG-000154827 - Reflected XSS in ArcGIS Experience Builder
Published 2024-10-04 · Modified
5.4EPSS 0.006
CVE-2022-38189
There is a stored cross-site scripting (XSS) vulnerability in ArcGIS API for JavaScript.
Published 2022-08-16 · Modified
5.4EPSS 0.006
CVE-2024-25705
Cross site scripting issue in embed widget
Published 2024-04-04 · Analyzed
5.4EPSS 0.005
CVE-2023-25833
BUG-000155004 HTML injection issue in Portal for ArcGIS.
Published 2023-05-10 · Modified
5.4EPSS 0.004
CVE-2023-25836
BUG-000135364 XSS in 10.8.1 sites builder iframe source
Published 2023-07-21 · Analyzed
5.4EPSS 0.004
CVE-2024-25697
Stored XSS in Portal for ArcGIS
Published 2024-04-04 · Modified
5.4EPSS 0.004
CVE-2023-25834
BUG-000142922 Incomplete permission changes in specific cases.
Published 2023-05-09 · Modified
5.4EPSS 0.003
CVE-2024-38039
BUG-000161683 - HTML injection vulnerability in Portal for ArcGIS.
Published 2024-10-04 · Analyzed
5.4EPSS 0.003
CVE-2026-69229
HTML injection vulnerability in Esri Portal for ArcGIS
Published 2026-08-21 · Analyzed
5.4EPSS 0.003
CVE-2024-25692
BUG-000154722 - Cross-site request forgery (CSRF) issue in Portal for ArcGIS
Published 2024-04-04 · Modified
5.4EPSS 0.002
CVE-2026-69228
missing authentication vulnerability in Esri Portal for ArcGIS
Published 2026-08-21 · Analyzed
5.3EPSS 0.005
CVE-2024-25696
Stored XSS in Portal for ArcGIS
Published 2024-04-04 · Modified
4.8EPSS 0.004
CVE-2024-25707
BUG-000160241 - Reflected XSS in Portal for ArcGIS
Published 2024-10-04 · Analyzed
4.8EPSS 0.004
CVE-2024-25701
BUG-000160765 - Stored XSS in ArcGIS Experience Builder
Published 2024-10-04 · Modified
4.8EPSS 0.003
CVE-2024-25702
BUG-000160599 - Stored XSS in Portal for ArcGIS Web App Builder
Published 2024-10-04 · Modified
4.8EPSS 0.003
CVE-2026-69237
HTML injection vulnerability in Esri Portal for ArcGIS
Published 2026-08-21 · Analyzed
4.8EPSS 0.003
CVE-2024-25694
BUG-000163019 - Stored XSS in Portal for ArcGIS
Published 2024-10-04 · Modified
4.8EPSS 0.003
CVE-2026-69238
HTML injection vulnerability in Esri Portal for ArcGIS
Published 2026-08-21 · Analyzed
4.8EPSS 0.002
CVE-2025-55103
BUG-000177333 - ArcGIS Enterprise Sites has a stored Cross-site Scripting vulnerability.
Published 2025-08-21 · Analyzed
4.8EPSS 0.002
CVE-2025-57871
BUG-000174020 - Reflected XSS vulnerability identified in Portal for ArcGIS. (11.3, 11.1, 10.9.1)
Published 2025-09-29 · Analyzed
4.8EPSS 0.002
CVE-2025-57873
BUG-000175222 - Reflected XSS vulnerability in Portal for ArcGIS.
Published 2025-09-29 · Analyzed
4.8EPSS 0.002
CVE-2025-57874
BUG-000161627 - Reflected XSS vulnerability in Portal for ArcGIS.  (11.3, 11.1, 10.9.1)
Published 2025-09-29 · Analyzed
4.8EPSS 0.002
CVE-2025-57877
Reflected XSS vulnerability in Portal for ArcGIS.
Published 2025-09-29 · Analyzed
4.8EPSS 0.002
← Prev2 / 3Next →