Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

ArcGIS Server — Vulnerabilities & Security Advisories 58

All 58 CVE vulnerabilities found in ArcGIS Server, with AI-generated Chinese analysis, references, and POCs.

This page documents known Common Weakness Enumerations (CWE) affecting Esri’s ArcGIS Server enterprise software. It aggregates security vulnerabilities linked to the platform, focusing on weaknesses such as insecure configuration, cross-site scripting, and improper access control mechanisms inherent to its architecture. The collection encompasses publicly disclosed security issues, vendor advisory bulletins, and confirmed exploitation cases ranging from the early release cycles of ArcGIS Server 9.x through the most recent ArcGIS Enterprise 11.x versions. This historical scope allows stakeholders to analyze long-term security trends and remediation patterns across major software updates and service packs. Users can leverage this resource to track Esri’s security advisory release cadence, understand the technical implications of specific weakness classes within the ArcGIS ecosystem, and look up the vulnerability history of specific product versions. This information supports risk assessment, patch management planning, and secure deployment configurations by providing a centralized view of the threat landscape. By correlating weakness types with affected component releases, administrators can prioritize mitigation efforts and validate compliance with organizational security policies. The data is structured to facilitate rapid identification of relevant risks without requiring extensive manual research across disparate vendor announcements or third-party databases.

Vendor: Esri

CVE ID Title CVSS Severity Published
CVE-2026-9181 Directory Traversal in ArcGIS Server CWE-22 9.8 Critical 2026-07-06
CVE-2026-9182 Unvalidated File Upload vulnerability in ArcGIS Server. CWE-434 9.8 Critical 2026-07-06
CVE-2026-2813 Unvalidated Redirect in ArcGIS Server 4.7 Medium 2026-05-20
CVE-2026-2812 Improper Authentication issue in ArcGIS Server CWE-287 5.3 Medium 2026-05-20
CVE-2025-67711 Reflected XSS vulnerability in ArcGIS Server. CWE-79 6.1 Medium 2025-12-31
CVE-2025-67710 Stored XSS vulnerability in ArcGIS Server CWE-79 6.1 Medium 2025-12-31
CVE-2025-67709 There is a cross site scripting issue in ArcGIS Server. CWE-79 6.1 Medium 2025-12-31
CVE-2025-67708 Reflected cross-site scripting (XSS) vulnerability in ArcGIS Server. CWE-79 6.1 Medium 2025-12-31
CVE-2025-67707 Unvalidated File Upload vulnerability in ArcGIS Server. CWE-434 5.6 Medium 2025-12-31
CVE-2025-67706 Unvalidated File Upload vulnerability in ArcGIS Server. CWE-434 5.6 Medium 2025-12-31
CVE-2025-67705 Reflected XSS vulnerability in ArcGIS Server. CWE-79 6.1 Medium 2025-12-31
CVE-2025-67704 Stored XSS vulnerability in ArcGIS Server. CWE-79 6.1 Medium 2025-12-31
CVE-2025-67703 Stored XSS vulnerability in ArcGIS Server. CWE-79 6.1 Medium 2025-12-31
CVE-2025-57870 BUG-000179884 - There is a security vulnerability in ArcGIS Server Feature Services. CWE-89 10.0 Critical 2025-10-22
CVE-2024-51966 Directory traversal vulnerability in ArcGIS Server CWE-22 4.9 Medium 2025-03-03
CVE-2024-51963 Stored XSS in ArcGIS Server Manager CWE-79 4.8 Medium 2025-03-03
CVE-2024-51962 SQL injection vulnerability in ArcGIS Server CWE-89 8.7 High 2025-03-03
CVE-2024-51961 Local file inclusion (LFI) vulnerability in ArcGIS Server CWE-73 7.5 High 2025-03-03
CVE-2024-51960 Stored XSS in ArcGIS Server Administrator Directory CWE-79 4.8 Medium 2025-03-03
CVE-2024-51959 Stored XSS issue in Server Admin API CWE-79 4.8 Medium 2025-03-03
CVE-2024-51958 Directory traversal vulnerability in the admin api for service thumbnails CWE-22 4.9 Medium 2025-03-03
CVE-2024-51957 Stored XSS vulnerability in ArcGIS Rest Services Directory CWE-79 4.8 Medium 2025-03-03
CVE-2024-51956 Stored XSS vulnerability in ArcGIS Server Administrator Directory CWE-79 4.8 Medium 2025-03-03
CVE-2024-51954 Unauthorized access to secure services in ArcGIS Server CWE-284 8.5 High 2025-03-03
CVE-2024-51953 Stored XSS in ArcGIS Server Rest services CWE-79 4.8 Medium 2025-03-03
CVE-2024-51952 Stored XSS issue in ArcGIS Server CWE-79 4.8 Medium 2025-03-03
CVE-2024-51951 Stored XSS in Server Admin API CWE-79 4.8 Medium 2025-03-03
CVE-2024-51950 Stored XSS in Server Admin under Services > lifecycleinfos CWE-79 4.8 Medium 2025-03-03
CVE-2024-51949 Stored XSS vulnerability in Rest Services under OGCFeature Service and Map Service CWE-79 4.8 Medium 2025-03-03
CVE-2024-51948 Stored XSS vulnerability in Rest Services under Job ID CWE-79 4.8 Medium 2025-03-03

All 58 known CVE vulnerabilities affecting ArcGIS Server with full Chinese analysis, references, and POCs where available.