Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Esri — Vulnerabilities & Security Advisories 167

Browse all 167 CVE security advisories affecting Esri. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Esri develops geographic information system (GIS) software, enabling organizations to map, analyze, and visualize spatial data for urban planning, logistics, and environmental management. The company’s extensive portfolio, including ArcGIS Server and Portal for ArcGIS, has historically been associated with 147 recorded Common Vulnerabilities and Exposures (CVEs). These security flaws predominantly involve remote code execution, cross-site scripting, and privilege escalation, often stemming from improper input validation or insecure default configurations in web-facing components. While no single catastrophic breach has defined the vendor’s public history, the high volume of vulnerabilities highlights the complexity of securing large-scale enterprise GIS deployments. Many issues require administrative access to exploit, yet successful attacks can lead to full system compromise or data exfiltration. Continuous patching and strict network segmentation remain critical for mitigating risks associated with these legacy and modern software components within critical infrastructure environments.

CVE ID Title CVSS Severity Published
CVE-2022-38209 Reflected XSS vulnerability in Portal for ArcGIS — ArcGIS Quickcapture CWE-79 6.1 Medium 2022-12-30
CVE-2022-38210 HTML injection in accountswitcher-callback.html (10.9.1, 10.8.1 and 10.7.1 only) — ArcGIS Enterprise CWE-80 6.1 Medium 2022-12-30
CVE-2022-38211 Server Side Request Forgery (SSRF) vulnerability in Portal for ArcGIS (10.9.1, 10.8.1 and 10.7.1 only) — ArcGIS Enterprise CWE-918 7.5 High 2022-12-30
CVE-2022-38212 Server Side Request Forgery (SSRF) vulnerability in Portal for ArcGIS (10.8.1 and 10.7.1 only) — ArcGIS Enterprise CWE-918 7.5 High 2022-12-30
CVE-2022-38202 BUG-000152121 - Directory traversal vulnerability in ArcGIS Server. — ArcGIS Server CWE-23 7.5 High 2022-12-28
CVE-2022-38201 An unvalidated redirect vulnerability exists in Esri ArcGIS Quick Capture Web Designer versions 10.8.1 to 10.9.1. — ArcGIS Quickcapture CWE-601 6.1 Medium 2022-11-15
CVE-2022-38195 BUG-000150540 - Reflected XSS vulnerability in ArcGIS Server — ArcGIS Server CWE-79 6.1 Medium 2022-10-25
CVE-2022-38196 BUG-000150537 - ArcGIS Server has a local file inclusion (LFI) vulnerability — ArcGIS Server CWE-22 6.5 Medium 2022-10-25
CVE-2022-38197 BUG-000148347 Unvalidated redirect issues in ArcGIS Server. — ArcGIS Server CWE-601 6.1 Medium 2022-10-25
CVE-2022-38198 BUG-000146513 - Reflected XSS vulnerability in ArcGIS Server — ArcGIS Server CWE-79 6.1 Medium 2022-10-25
CVE-2022-38199 BUG-000144172 - Remote file download issue in ArcGIS Server — ArcGIS Server CWE-494 6.1 Medium 2022-10-25
CVE-2022-38200 BUG-000142376 - Reflected Cross-Site Scripting (XSS) vulnerability in ArcGIS Server. — ArcGIS Server CWE-79 6.1 Medium 2022-10-25
CVE-2022-38189 There is a stored cross-site scripting (XSS) vulnerability in ArcGIS API for JavaScript. — Portal for ArcGIS CWE-79 5.4 Medium 2022-08-16
CVE-2022-38184 There is an improper access control vulnerability in Portal for ArcGIS versions 10.8.1 — Portal for ArcGIS CWE-284 7.5 High 2022-08-16
CVE-2022-38192 There is a stored cross-site scripting (XSS) vulnerability in ArcGIS API for JavaScript. — Portal for ArcGIS CWE-79 6.1 Medium 2022-08-16
CVE-2022-38193 Code injection issue in Portal for ArcGIS (10.7.1 and 10.8.1) — Portal for ArcGIS CWE-95 6.1 Medium 2022-08-16
CVE-2022-38194 Portal for ArcGIS system properties are not properly encrypted (10.8.1 only) — Portal for ArcGIS CWE-311 6.7 Medium 2022-08-16
CVE-2022-38191 HTML injection vulnerability in Portal for ArcGIS — Portal for ArcGIS CWE-74 6.1 Medium 2022-08-15
CVE-2022-38187 Prevent access to sharing/rest/content/features/analyze to unauthorized users — Portal for ArcGIS CWE-918 7.5 High 2022-08-15
CVE-2022-38188 Esri Portal For ArcGis 跨站脚本漏洞 — Portal for ArcGIS CWE-79 6.1 - 2022-08-15
CVE-2022-38190 Stored cross-site scripting vulnerability in Esri Portal for ArcGIS Configurable Apps — Portal for ArcGIS CWE-79 6.1 Medium 2022-08-15
CVE-2022-38186 Esri Portal For ArcGis 跨站脚本漏洞 — Portal for ArcGIS CWE-79 6.1 - 2022-08-15
CVE-2021-29117 arcreader use-after-free — ArcReader CWE-416 7.8 - 2022-08-12
CVE-2021-29112 Esri ArcReader PMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability — ArcReader CWE-125 5.5 - 2022-08-12
CVE-2021-29118 Esri ArcReader PMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability — ArcReader CWE-125 5.5 - 2022-08-12
CVE-2021-29116 BUG-000142180 Hosted feature services vulnerable to stored XSS — ArcGIS Server CWE-79 6.1 - 2021-12-07
CVE-2021-29115 An information disclosure vulnerability — ArcGIS Server CWE-200 5.3 - 2021-12-07
CVE-2021-29114 SQL injection vulnerability in ArcGIS Server — ArcGIS Server CWE-89 9.8 - 2021-12-07
CVE-2021-29113 Remote file inclusion vulnerability in ArcGIS Server help documentation — ArcGIS Server CWE-98 4.7 - 2021-12-07
CVE-2021-29110 Stored cross-site scripting (XSS) issue in Esri Portal for ArcGIS may allow a remote unauthenticated attacker to pass and store malicious strings in the home application. — Portal for ArcGIS CWE-79 5.4 - 2021-10-01

This page lists every published CVE security advisory associated with Esri. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.