Esri ArcGIS Hub and ArcGIS Enterprise Sites Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in Esri ArcGIS Hub and ArcGIS Enterprise Sites, affecting versions through 11.4. This vulnerability allows authenticated users with the ability to create or edit a site to inject and store XSS payloads. When triggered, these payloads execute attacker-supplied JavaScript in the context of the victim's browser.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user.

Remediation

Esri has released a patch for this vulnerability as part of the Portal for ArcGIS Enterprise Sites Security 2025 Update 1 Patch. This patch is available through the Esri Support website. Users should also implement the 2025 Top 3 New Critical Security Recommendations.

Added: Aug 21, 2025, 8:24 PM
Updated: Aug 21, 2025, 8:24 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
1.7
exploitability
4.6
remediation
7.7
relevance
0.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.