Stored Cross-Site Scripting Vulnerability in Esri ArcGIS Server
CVE-2025-67705

6.1MEDIUM

Key Information:

Vendor

Esri

Vendor
CVE Published:
31 December 2025

What is CVE-2025-67705?

A stored cross-site scripting (XSS) vulnerability exists in Esri ArcGIS Server, affecting version 11.4 and earlier on both Windows and Linux platforms. This vulnerability allows a remote unauthenticated attacker to store malicious code, which could be executed within the context of a victim's browser. In certain configurations, this could lead to unauthorized actions and potential data exposure, posing significant risks to users and organizations relying on the affected software for critical mapping and geographical information services.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

ArcGIS Server Windows 10.9.1 <= 11.4

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.