Esri
Esri Portal FOR Arcgis: vulnerabilidades y CVE
Esri Portal FOR Arcgis tiene 88 vulnerabilidades publicadas, 17 de ellas en los últimos 12 meses. 7 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE88
Últimos 12 meses17
Críticas7
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-69238 | Media (4.8) | 0.24% | — | 21 ago 2026 | There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.5 and prior that allows a remote, highly priviliged attacker to insert arbitrary HTML into the Portal for ArcGIS Home application. Users… |
| CVE-2026-69237 | Media (4.8) | 0.29% | — | 21 ago 2026 | There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.3 and prior that allows a remote attacker with administrative privileges to insert arbitrary HTML into an administrative API. Users working… |
| CVE-2026-69236 | Media (6.1) | 0.30% | — | 21 ago 2026 | There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 12.1 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in… |
| CVE-2026-69235 | Media (6.1) | 0.30% | — | 21 ago 2026 | There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s… |
| CVE-2026-69234 | Media (6.1) | 0.34% | — | 21 ago 2026 | There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS versions 11.5 and prior which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially… |
| CVE-2026-69233 | Media (5.5) | 0.27% | — | 21 ago 2026 | There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged attacker to inject malicious code that could potentially execute… |
| CVE-2026-69232 | Media (5.5) | 0.33% | — | 21 ago 2026 | There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in… |
| CVE-2026-69231 | Media (5.5) | 0.33% | — | 21 ago 2026 | There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in… |
| CVE-2026-69230 | Media (4.8) | 0.24% | — | 21 ago 2026 | There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged attacker to inject malicious code that could potentially execute… |
| CVE-2026-69229 | Media (5.4) | 0.27% | — | 21 ago 2026 | There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that allows a remote, authenticated attacker to insert arbitrary HTML into the Portal for ArcGIS Home application. Users working… |
| CVE-2026-69228 | Media (5.3) | 0.48% | — | 21 ago 2026 | There is a missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that may allow a remote, unauthenticated attacker to access a specific resource (not user content) that should only be… |
| CVE-2026-69225 | Alta (7.5) | 0.46% | — | 21 ago 2026 | There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 11.5 through 12.0 and earlier that may allow a remote, unauthenticated attacker to reflect sensitive information in a http response… |
| CVE-2026-69224 | Alta (7.5) | 0.46% | — | 21 ago 2026 | There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 12.0 and earlier that may under difficult to reproduce circumstances allow a remote, unauthenticated attacker to reflect sensitive… |
| CVE-2026-13020 | Crítica (9.8) | 0.47% | — | 7 jul 2026 | A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s… |
| CVE-2026-13019 | Crítica (9.8) | 0.85% | — | 7 jul 2026 | Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API.… |
| CVE-2026-33519 | Crítica (9.8) | 0.48% | — | 21 abr 2026 | An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials. |
| CVE-2026-33518 | Alta (7.2) | 0.47% | — | 21 abr 2026 | An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to create developer credentials that may grant more privileges than expected. |
| CVE-2025-57879 | Media (6.1) | 0.25% | — | 29 sept 2025 | There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying… |
| CVE-2025-57878 | Media (6.1) | 0.25% | — | 29 sept 2025 | There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying… |
| CVE-2025-57877 | Media (4.8) | 0.22% | — | 29 sept 2025 | There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote authenticated attacker with administrative access to supply a crafted string which would execute… |
| CVE-2025-57874 | Media (4.8) | 0.22% | — | 29 sept 2025 | There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote authenticated attacker with administrative access to supply a crafted string which would execute… |
| CVE-2025-57873 | Media (4.8) | 0.22% | — | 29 sept 2025 | There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote authenticated attacker with administrative access to supply a crafted string which would execute… |
| CVE-2025-57872 | Media (6.1) | 0.25% | — | 29 sept 2025 | There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying… |
| CVE-2025-57876 | Media (4.8) | 0.22% | — | 29 sept 2025 | There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, authenticated attacker to inject malicious a file with an embedded xss script which when loaded… |
| CVE-2025-57875 | Media (4.8) | 0.22% | — | 29 sept 2025 | There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote authenticated attacker with administrative access to supply a crafted string which would execute… |
| CVE-2025-57871 | Media (4.8) | 0.22% | — | 29 sept 2025 | There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote authenticated attacker with administrative access to supply a crafted string which would execute… |
| CVE-2025-55107 | Media (4.8) | 0.22% | — | 21 ago 2025 | — |
| CVE-2025-55106 | Media (4.8) | 0.22% | — | 21 ago 2025 | There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites versions 10.9.1 – 11.4 that may allow a remote, authenticated attacker to inject malicious a file with an embedded xss… |
| CVE-2025-55105 | Media (4.8) | 0.22% | — | 21 ago 2025 | There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites versions 10.9.1 – 11.4 that may allow a remote, authenticated attacker to inject malicious a file with an embedded xss… |
| CVE-2025-55104 | Media (4.8) | 0.19% | — | 21 ago 2025 | A stored cross-site scripting (XSS) vulnerability exists ArcGIS HUB and ArcGIS Enterprise Sites which allows an authenticated user with the ability to create or edit a site to add and store an XSS payload. If this… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.