{"id":"CVE-2025-67709","title":"There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in …","summary":"There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in …","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"esri","product":"arcgis_server","affected":["arcgis_server <= 11.5"],"published":"2025-12-31","updated":"2026-09-23","sourceUpdated":"2026-09-23T14:10:00.190","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-67709","references":[{"url":"https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-server-security-2025-update-2-patch","label":"psirt@esri.com"}],"tags":["nvd"],"epss":0.0023,"epssPercentile":0.14093,"ingestedAt":"2026-09-23T14:25:29.788Z","slug":"CVE-2025-67709","body":"## Overview\n\nThere is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.\n\n## Affected\n\n- `arcgis_server <= 11.5`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}