Browse all 167 CVE security advisories affecting Esri. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Esri develops geographic information system (GIS) software, enabling organizations to map, analyze, and visualize spatial data for urban planning, logistics, and environmental management. The company’s extensive portfolio, including ArcGIS Server and Portal for ArcGIS, has historically been associated with 147 recorded Common Vulnerabilities and Exposures (CVEs). These security flaws predominantly involve remote code execution, cross-site scripting, and privilege escalation, often stemming from improper input validation or insecure default configurations in web-facing components. While no single catastrophic breach has defined the vendor’s public history, the high volume of vulnerabilities highlights the complexity of securing large-scale enterprise GIS deployments. Many issues require administrative access to exploit, yet successful attacks can lead to full system compromise or data exfiltration. Continuous patching and strict network segmentation remain critical for mitigating risks associated with these legacy and modern software components within critical infrastructure environments.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2022-38190 | Stored cross-site scripting vulnerability in Esri Portal for ArcGIS Configurable Apps — Portal for ArcGIS CWE-79 | 6.1 | Medium | 2022-08-15 |
| CVE-2022-38186 | Esri Portal For ArcGis 跨站脚本漏洞 — Portal for ArcGIS CWE-79 | 6.1 | - | 2022-08-15 |
| CVE-2021-29110 | Stored cross-site scripting (XSS) issue in Esri Portal for ArcGIS may allow a remote unauthenticated attacker to pass and store malicious strings in the home application. — Portal for ArcGIS CWE-79 | 5.4 | - | 2021-10-01 |
| CVE-2021-29109 | A reflected XSS vulnerability in Esri Portal for ArcGIS version 10.9. — Portal for ArcGIS CWE-79 | 6.1 | - | 2021-10-01 |
| CVE-2021-29108 | There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below. — Portal for ArcGIS CWE-347 | 8.8 | High | 2021-10-01 |
This page lists every published CVE security advisory associated with Esri. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.