Stored Cross-Site Scripting Vulnerability in ArcGIS HUB and ArcGIS Enterprise Sites
CVE-2025-55104
What is CVE-2025-55104?
A stored cross-site scripting (XSS) vulnerability exists in ArcGIS HUB and ArcGIS Enterprise Sites, allowing an authenticated user with site creation or editing privileges to insert and store malicious XSS payloads. When triggered, these payloads can execute arbitrary JavaScript in the browsers of unsuspecting users, potentially leading to data theft, user impersonation, or further attacks on the affected web applications. Organizations using these Esri products should ensure their user roles are appropriately managed and implement safety measures to mitigate potential exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Portal for ArcGIS Enterprise Sites Windows 10.9.1 <= 11.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
