VYPR

Portal For Arcgis

by Esri

CVEs (88)

  • CVE-2024-25694MedOct 4, 2024
    risk 0.31cvss 4.8epss 0.00

    There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise versions 11.1 and below that may allow a remote, authenticated attacker to create a crafted link that is stored in the Layer Showcase application configuration which when clicked could…

  • CVE-2024-25696MedApr 4, 2024
    risk 0.31cvss 4.8epss 0.00

    There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.0 and below that may allow a remote, authenticated attacker to create a crafted link which when accessing the page editor an image will render in the victim’s browser. The privileges required to…

  • CVE-2024-25690MedApr 4, 2024
    risk 0.31cvss 4.7epss 0.00

    There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.1 and below that may allow a remote, unauthenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser.

  • CVE-2024-8149MedOct 4, 2024
    risk 0.30cvss 4.6epss 0.00

    There is a reflected Cross‑Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS versions 11.1 and 11.2 that may allow a remote, authenticated attacker with low‑privileged access to create a crafted link which, when clicked, could potentially execute arbitrary…

  • CVE-2026-69237LowAug 21, 2026
    risk 0.25cvss 3.8epss 0.00

    There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.3 and prior that allows a remote attacker with administrative privileges to insert arbitrary HTML into an administrative API. Users working with ArcGIS Enterprise 11.1, and 11.3 are encouraged to…

  • CVE-2026-69238LowAug 21, 2026
    risk 0.23cvss 3.5epss 0.00

    There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.5 and prior that allows a remote, highly priviliged attacker to insert arbitrary HTML into the Portal for ArcGIS Home application. Users working with ArcGIS Enterprise 11.1, 11.3, and 11.5 are…

  • CVE-2026-13020HigJul 7, 2026
    risk 0.00cvss 8.1epss 0.00

    A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators…

  • CVE-2026-13019CriJul 7, 2026
    risk 0.00cvss 9.8epss 0.01

    Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API.

Page 5 of 5