HTML Injection in Esri ArcGIS Web AppBuilder Developer Edition
CVE-2025-67712

4.7MEDIUM

Key Information:

Vendor

Esri

Vendor
CVE Published:
19 December 2025

What is CVE-2025-67712?

The ArcGIS Web AppBuilder Developer Edition prior to version 2.30 contains a vulnerability allowing remote, unauthenticated attackers to exploit an HTML injection issue. This flaw entails enticing users to click on malicious links, leading to the rendering of arbitrary HTML in their browsers. While JavaScript execution remains unproven, users of the affected versions should be aware that the developer edition is retired and without support, emphasizing the importance of upgrading to version 2.30 to mitigate potential risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

ArcGIS Web AppBuilder {Developer Edition) Windows all <= 2.30

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.