Esri ArcGIS Enterprise Sites
cpe:2.3:a:esri:arcgis_enterprise:*:*:*:*:*:*:*
- <= 11.4
A stored cross-site scripting vulnerability has been identified in Esri ArcGIS Hub and ArcGIS Enterprise Sites, affecting versions through 11.4. This vulnerability allows authenticated users with the ability to create or edit a site to inject and store XSS payloads. When triggered, these payloads execute attacker-supplied JavaScript in the context of the victim's browser.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user.
Esri has released a patch for this vulnerability as part of the Portal for ArcGIS Enterprise Sites Security 2025 Update 1 Patch. This patch is available through the Esri Support website. Users should also implement the 2025 Top 3 New Critical Security Recommendations.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.