VendorsEsriportal_for_arcgisany version
Vulnerabilities

Esri Portal any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

61CVEs
CVE-2024-25705
Cross site scripting issue in embed widget
Published 2024-04-04 · Analyzed
5.4EPSS 0.005
CVE-2023-25833
BUG-000155004 HTML injection issue in Portal for ArcGIS.
Published 2023-05-10 · Modified
5.4EPSS 0.004
CVE-2023-25836
BUG-000135364 XSS in 10.8.1 sites builder iframe source
Published 2023-07-21 · Analyzed
5.4EPSS 0.004
CVE-2024-25697
Stored XSS in Portal for ArcGIS
Published 2024-04-04 · Modified
5.4EPSS 0.004
CVE-2023-25834
BUG-000142922 Incomplete permission changes in specific cases.
Published 2023-05-09 · Modified
5.4EPSS 0.003
CVE-2024-38039
BUG-000161683 - HTML injection vulnerability in Portal for ArcGIS.
Published 2024-10-04 · Analyzed
5.4EPSS 0.003
CVE-2026-69229
HTML injection vulnerability in Esri Portal for ArcGIS
Published 2026-08-21 · Analyzed
5.4EPSS 0.003
CVE-2024-25692
BUG-000154722 - Cross-site request forgery (CSRF) issue in Portal for ArcGIS
Published 2024-04-04 · Modified
5.4EPSS 0.002
CVE-2026-69228
missing authentication vulnerability in Esri Portal for ArcGIS
Published 2026-08-21 · Analyzed
5.3EPSS 0.005
CVE-2024-25696
Stored XSS in Portal for ArcGIS
Published 2024-04-04 · Modified
4.8EPSS 0.004
CVE-2024-25707
BUG-000160241 - Reflected XSS in Portal for ArcGIS
Published 2024-10-04 · Analyzed
4.8EPSS 0.004
CVE-2026-69237
HTML injection vulnerability in Esri Portal for ArcGIS
Published 2026-08-21 · Analyzed
4.8EPSS 0.003
CVE-2024-25702
BUG-000160599 - Stored XSS in Portal for ArcGIS Web App Builder
Published 2024-10-04 · Modified
4.8EPSS 0.003
CVE-2024-25701
BUG-000160765 - Stored XSS in ArcGIS Experience Builder
Published 2024-10-04 · Modified
4.8EPSS 0.003
CVE-2024-25694
BUG-000163019 - Stored XSS in Portal for ArcGIS
Published 2024-10-04 · Modified
4.8EPSS 0.003
CVE-2026-69238
HTML injection vulnerability in Esri Portal for ArcGIS
Published 2026-08-21 · Analyzed
4.8EPSS 0.002
CVE-2025-55107
BUG-000177335 ArcGIS Enterprise Sites has a stored Cross-site Scripting vulnerability.
Published 2025-08-21 · Analyzed
4.8EPSS 0.002
CVE-2025-55106
BUG-000173171 ArcGIS Enterprise Sites has a Cross-site Scripting vulnerability.
Published 2025-08-21 · Analyzed
4.8EPSS 0.002
CVE-2025-55105
BUG-000177336 - ArcGIS Enterprise Sites has a stored Cross-site Scripting vulnerability.
Published 2025-08-21 · Analyzed
4.8EPSS 0.002
CVE-2025-55104
BUG-000173918 - ArcGIS Enterprise Sites has a security vulnerability.
Published 2025-08-21 · Analyzed
4.8EPSS 0.002
CVE-2024-25690
HTML injection in ArcGIS Web AppBuilder
Published 2024-04-04 · Analyzed
4.7EPSS 0.005
← Prev2 / 2