MEDIUM
Reflected XSS vulnerability in ArcGIS Server.
Published Dec 31, 2025
6.1
MEDIUMCVSS 3.1
EPSS 0.24%
Description
There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.
Affected products
-
Affected
- ≥ 10.9.1, ≤ 11.4
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Esri | ArcGIS Server | unaffected | Affected
|
AND
- ≤ 11.5
Running on/with
OR
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-206102 Advisory
- https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-server-security-2025-update-2-patch PatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-206102 | Advisory | |
| https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-server-security-2025-update-2-patch | PatchVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Esri
Published Dec 31, 2025
Updated Jan 2, 2026
Reserved Dec 10, 2025
Link CVE-2025-67705
CISA Vulnrichment
Updated Jan 2, 2026
Red Hat
No data
GitHub
No data