---
id: CVE-2025-67709
title: >-
  There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and
  earlier on Windows and Linux that in some configurations allows a remote
  unauthenticated attacker to store files that contain malicious code that may
  execute in …
summary: >-
  There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and
  earlier on Windows and Linux that in some configurations allows a remote
  unauthenticated attacker to store files that contain malicious code that may
  execute in …
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: esri
product: arcgis_server
affected:
  - arcgis_server <= 11.5
published: '2025-12-31'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T14:10:00.190'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-67709'
references:
  - url: >-
      https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-server-security-2025-update-2-patch
    label: psirt@esri.com
tags:
  - nvd
epss: 0.0023
epssPercentile: 0.14097
ingestedAt: '2026-09-23T14:25:29.788Z'
---

## Overview

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.

## Affected

- `arcgis_server <= 11.5`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
