Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Esri — Vulnerabilities & Security Advisories 167

Browse all 167 CVE security advisories affecting Esri. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Esri develops geographic information system (GIS) software, enabling organizations to map, analyze, and visualize spatial data for urban planning, logistics, and environmental management. The company’s extensive portfolio, including ArcGIS Server and Portal for ArcGIS, has historically been associated with 147 recorded Common Vulnerabilities and Exposures (CVEs). These security flaws predominantly involve remote code execution, cross-site scripting, and privilege escalation, often stemming from improper input validation or insecure default configurations in web-facing components. While no single catastrophic breach has defined the vendor’s public history, the high volume of vulnerabilities highlights the complexity of securing large-scale enterprise GIS deployments. Many issues require administrative access to exploit, yet successful attacks can lead to full system compromise or data exfiltration. Continuous patching and strict network segmentation remain critical for mitigating risks associated with these legacy and modern software components within critical infrastructure environments.

CVE ID Title CVSS Severity Published
CVE-2024-51953 Stored XSS in ArcGIS Server Rest services — ArcGIS Server CWE-79 4.8 Medium 2025-03-03
CVE-2024-51952 Stored XSS issue in ArcGIS Server — ArcGIS Server CWE-79 4.8 Medium 2025-03-03
CVE-2024-51951 Stored XSS in Server Admin API — ArcGIS Server CWE-79 4.8 Medium 2025-03-03
CVE-2024-51950 Stored XSS in Server Admin under Services > lifecycleinfos — ArcGIS Server CWE-79 4.8 Medium 2025-03-03
CVE-2024-51949 Stored XSS vulnerability in Rest Services under OGCFeature Service and Map Service — ArcGIS Server CWE-79 4.8 Medium 2025-03-03
CVE-2024-51948 Stored XSS vulnerability in Rest Services under Job ID — ArcGIS Server CWE-79 4.8 Medium 2025-03-03
CVE-2024-51947 Stored XSS vulnerability in Rest Services under Layer name — ArcGIS Server CWE-79 4.8 Medium 2025-03-03
CVE-2024-51946 Stored XSS in Rest Services Directory under Identify operation — ArcGIS Server CWE-79 4.8 Medium 2025-03-03
CVE-2024-51945 Stored XSS issues in Server Admin API — ArcGIS Server CWE-79 4.8 Medium 2025-03-03
CVE-2024-51944 Stored XSS in Rest Services Directory — ArcGIS Server CWE-79 4.8 Medium 2025-03-03
CVE-2024-51942 Stored XSS vulnerability in Rest Admin API under Hosted Feature Services page — ArcGIS Server CWE-79 4.8 Medium 2025-03-03
CVE-2024-10904 Stored XSS in Server Admin API — ArcGIS Server CWE-79 4.8 Medium 2025-03-03
CVE-2024-5888 Stored XSS in Rest Services API for a Toolbox published as GP Service — ArcGIS Server CWE-79 4.8 Medium 2025-03-03
CVE-2025-1726 [#BUG-000172669 ArcGIS Monitor has a security vulnerability] — ArcGIS Monitor CWE-89 4.3 Medium 2025-02-26
CVE-2025-1068 There is a code injection vulnerability in Esri ArcGIS AllSource — ArcGIS AllSource CWE-426 7.3 High 2025-02-25
CVE-2025-1067 There is a code injection vulnerability in ArcGIS Pro — ArcGIS Pro CWE-732 7.3 High 2025-02-25
CVE-2024-38040 BUG-000167984 - Portal for ArcGIS has a Local file inclusion (LFI) vulnerability — Portal for ArcGIS CWE-73 7.5 High 2024-10-04
CVE-2024-38038 BUG-000165732 - Reflected XSS in Portal for ArcGIS — Portal for ArcGIS CWE-79 6.1 Medium 2024-10-04
CVE-2024-25691 BUG-000165286 - Reflected XSS in Portal for ArcGIS — Portal for ArcGIS CWE-79 6.1 Medium 2024-10-04
CVE-2024-25694 BUG-000163019 - Stored XSS in Portal for ArcGIS — Enterprise Web App Builder CWE-79 4.8 Medium 2024-10-04
CVE-2024-25701 BUG-000160765 - Stored XSS in ArcGIS Experience Builder — Portal for ArcGIS Enterprise Experience Builder CWE-79 4.8 Medium 2024-10-04
CVE-2024-25702 BUG-000160599 - Stored XSS in Portal for ArcGIS Web App Builder — ArcGIS Enterprise Web App Builder CWE-79 4.8 Medium 2024-10-04
CVE-2024-25707 BUG-000160241 - Reflected XSS in Portal for ArcGIS — Portal for ArcGIS CWE-79 4.8 Medium 2024-10-04
CVE-2024-38036 BUG-000154827 - Reflected XSS in ArcGIS Experience Builder — Portal for ArcGIS Enterprise Experience Builder CWE-79 5.4 Medium 2024-10-04
CVE-2024-8149 BUG-000168624 - Unvalidated redirect in Portal for ArcGIS. — Portal for ArcGIS CWE-79 4.6 Medium 2024-10-04
CVE-2024-38039 BUG-000161683 - HTML injection vulnerability in Portal for ArcGIS. — Portal for ArcGIS CWE-80 5.4 Medium 2024-10-04
CVE-2024-8148 BUG-000168624 - Unvalidated redirect in Portal for ArcGIS. (11.2, 11.1, 10.9.1. and 10.8.1) — Portal for ArcGIS CWE-601 6.1 Medium 2024-10-04
CVE-2024-38037 BUG-000167983 - Unvalidated redirect in Portal for ArcGIS — Portal for ArcGIS CWE-601 6.1 Medium 2024-10-04
CVE-2024-25699 Portal for ArcGIS has an invalid authentication vulnerability — Portal for ArcGIS CWE-287 8.5 High 2024-04-04
CVE-2024-25705 Cross site scripting issue in embed widget — Portal for ArcGIS CWE-79 5.4 Medium 2024-04-04

This page lists every published CVE security advisory associated with Esri. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.