📦 Portal For Arcgis

by Esri

🔍 What is Portal For Arcgis?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-2538

CRITICAL CVSS 9.8 Mar 20, 2025

A hardcoded credential vulnerability in Esri Portal for ArcGIS versions 11.4 and below allows remote unauthenticated attackers to gain administrative access. This affects systems deployed in a specifi...

CVE-2024-25693

CRITICAL CVSS 9.9 Apr 4, 2024

This path traversal vulnerability in Esri Portal for ArcGIS allows authenticated attackers to access files outside intended directories, potentially leading to sensitive data exposure or remote code e...

CVE-2024-38040

HIGH CVSS 7.5 Oct 4, 2024

A local file inclusion vulnerability in Esri Portal for ArcGIS allows remote unauthenticated attackers to craft URLs that read internal files, potentially exposing sensitive configuration data. This a...

CVE-2024-25699

HIGH CVSS 8.5 Apr 4, 2024

An improper authentication vulnerability in Esri Portal for ArcGIS and ArcGIS Enterprise allows authenticated low-privileged attackers to bypass authorization boundaries and gain unauthorized access. ...

CVE-2023-25837

HIGH CVSS 8.4 Jul 21, 2023

A stored cross-site scripting vulnerability in Esri ArcGIS Enterprise Sites allows authenticated high-privileged attackers to inject malicious JavaScript into links. When victims click these crafted l...

CVE-2023-25835

HIGH CVSS 8.4 Jul 21, 2023

A stored XSS vulnerability in Esri Portal for ArcGIS Sites allows authenticated high-privilege attackers to inject malicious JavaScript into site configurations. When victims access compromised links,...

CVE-2023-25832

HIGH CVSS 8.8 May 9, 2023

This cross-site request forgery (CSRF) vulnerability in Esri Portal for ArcGIS allows attackers to trick authenticated users into performing unintended actions on the portal. It affects versions 11.0 ...

CVE-2025-57878

MEDIUM CVSS 6.1 Sep 29, 2025

An unvalidated redirect vulnerability in Esri Portal for ArcGIS allows attackers to craft malicious URLs that redirect users to arbitrary websites. This can facilitate phishing attacks by making malic...

CVE-2025-57879

MEDIUM CVSS 6.1 Sep 29, 2025

This vulnerability allows remote attackers to create malicious URLs that redirect users to arbitrary websites without validation. It affects unauthenticated users of Esri Portal for ArcGIS versions 11...

CVE-2025-57872

MEDIUM CVSS 6.1 Sep 29, 2025

This CVE describes an unvalidated redirect vulnerability in Esri Portal for ArcGIS that allows attackers to craft malicious URLs. When clicked, these URLs can redirect victims to arbitrary external we...

CVE-2025-57873

MEDIUM CVSS 4.8 Sep 29, 2025

A reflected cross-site scripting (XSS) vulnerability in Esri Portal for ArcGIS versions 11.4 and below allows remote authenticated attackers with administrative privileges to inject malicious JavaScri...

CVE-2025-57874

MEDIUM CVSS 4.8 Sep 29, 2025

A reflected cross-site scripting (XSS) vulnerability in Esri Portal for ArcGIS versions 11.4 and below allows remote authenticated administrators to inject malicious JavaScript that executes in victim...

CVE-2025-57875

MEDIUM CVSS 4.8 Sep 29, 2025

A reflected cross-site scripting (XSS) vulnerability in Esri Portal for ArcGIS allows remote authenticated administrators to inject malicious JavaScript that executes in victims' browsers. This affect...

CVE-2025-57877

MEDIUM CVSS 4.8 Sep 29, 2025

A reflected cross-site scripting (XSS) vulnerability in Esri Portal for ArcGIS allows remote authenticated administrators to inject malicious JavaScript that executes in victims' browsers. This affect...

CVE-2025-57876

MEDIUM CVSS 4.8 Sep 29, 2025

A stored cross-site scripting vulnerability in Esri Portal for ArcGIS 11.4 and earlier allows authenticated attackers with high privileges to inject malicious files containing JavaScript. When victims...

CVE-2025-55104

MEDIUM CVSS 4.8 Aug 21, 2025

A stored cross-site scripting vulnerability in ArcGIS HUB and ArcGIS Enterprise Sites allows authenticated users with site creation/editing permissions to inject malicious JavaScript that executes in ...

CVE-2025-55105

MEDIUM CVSS 4.8 Aug 21, 2025

A stored cross-site scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites allows authenticated attackers with high privileges to inject malicious files containing JavaScript. When victims...

CVE-2025-55106

MEDIUM CVSS 4.8 Aug 21, 2025

A stored cross-site scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites allows authenticated attackers with high privileges to inject malicious files containing JavaScript. When victims...

CVE-2025-55107

MEDIUM CVSS 4.8 Aug 21, 2025

A stored cross-site scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites allows authenticated attackers with high privileges to inject malicious files containing JavaScript. When victims...

CVE-2024-8149

MEDIUM CVSS 4.6 Oct 4, 2024

A reflected Cross-Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS allows authenticated low-privileged attackers to craft malicious links that execute arbitrary JavaScript in victims' brow...

CVE-2024-38038

MEDIUM CVSS 6.1 Oct 4, 2024

A reflected cross-site scripting (XSS) vulnerability in Esri Portal for ArcGIS 11.1 allows attackers to craft malicious links that execute arbitrary JavaScript in victims' browsers when clicked. This ...

CVE-2024-38036

MEDIUM CVSS 5.4 Oct 4, 2024

A reflected cross-site scripting (XSS) vulnerability in Esri Portal for ArcGIS allows attackers to craft malicious links that execute arbitrary JavaScript in victims' browsers when clicked. This affec...

CVE-2024-25694

MEDIUM CVSS 4.8 Oct 4, 2024

A stored XSS vulnerability in Esri Portal for ArcGIS Enterprise allows authenticated attackers with high privileges to inject malicious JavaScript into the Layer Showcase application. When victims cli...

CVE-2024-25702

MEDIUM CVSS 4.8 Oct 4, 2024

A stored cross-site scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites allows authenticated attackers with high privileges to inject malicious JavaScript into site configurations. When...

CVE-2024-25709

MEDIUM CVSS 6.1 Apr 4, 2024

A stored XSS vulnerability in Esri Portal for ArcGIS allows remote authenticated attackers to inject malicious JavaScript via crafted links when moving items. This could execute arbitrary code in vict...

CVE-2024-25705

MEDIUM CVSS 5.4 Apr 4, 2024

A cross-site scripting (XSS) vulnerability in Esri Portal for ArcGIS Experience Builder allows authenticated low-privileged users to create malicious links that execute arbitrary JavaScript in victims...