VulnSea

esri has 15 CVEs on record. Disclosure cadence is accelerating: 13 in the last 90 days against 2 in the 90 before. The busiest recent month was August 2026 with 13. The median CVSS is 5.5 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-79 (10). Most affected products: portal_for_arcgis (13), arcgis_server (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.5
Publish → KEV
Last 90 days
13 prev 2

Products

  • portal_for_arcgis 13
  • arcgis_server 2
15
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

esri vulnerabilities

CVEs affecting esri, newest first. Open any entry for full detail, references, and exploit status.

15 CVEsRSS

CVE-2026-69238Low· 3.5
1mo ago

There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.5 and prior that allows a remote, highly priviliged attacker to insert arbitrary HTML into the Portal for ArcGIS Home application

There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.5 and prior that allows a remote, highly priviliged attacker to insert arbitrary HTML into the Portal for ArcGIS Home application. Users working with ArcGIS E…

Sunlitesri · portal_for_arcgisEPSS 0.14%via NVD
CVE-2026-69237Low· 3.8
1mo ago

There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.3 and prior that allows a remote attacker with administrative privileges to insert arbitrary HTML into an administrative API

There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.3 and prior that allows a remote attacker with administrative privileges to insert arbitrary HTML into an administrative API. Users working with ArcGIS Enterp…

Sunlitesri · portal_for_arcgisEPSS 0.17%via NVD
CVE-2026-69230Medium· 5.5
1mo ago

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s …

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s …

Sunlitesri · portal_for_arcgisEPSS 0.17%via NVD
CVE-2026-69229Medium· 5.4
1mo ago

There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that allows a remote, authenticated attacker to insert arbitrary HTML into the Portal for ArcGIS Home application

There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that allows a remote, authenticated attacker to insert arbitrary HTML into the Portal for ArcGIS Home application. Users working with ArcGIS Enter…

Sunlitesri · portal_for_arcgisEPSS 0.20%via NVD
CVE-2026-69228Medium· 5.3
1mo ago

There is a missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that may allow a remote, unauthenticated attacker to access a specific resource (not user content) that should only be accessible by authen…

There is a missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that may allow a remote, unauthenticated attacker to access a specific resource (not user content) that should only be accessible by authen…

Sunlitesri · portal_for_arcgisEPSS 0.34%via NVD
CVE-2026-69225Medium· 5.9
1mo ago

There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 11.5 through 12.0 and earlier that may allow a remote, unauthenticated attacker to reflect sensitive information in a http response body.

There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 11.5 through 12.0 and earlier that may allow a remote, unauthenticated attacker to reflect sensitive information in a http response body.

Sunlitesri · portal_for_arcgisEPSS 0.33%via NVD
CVE-2026-69224Medium· 5.9
1mo ago

There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 12.0 and earlier that may under difficult to reproduce circumstances allow a remote, unauthenticated attacker to reflect sensitive information in a http …

There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 12.0 and earlier that may under difficult to reproduce circumstances allow a remote, unauthenticated attacker to reflect sensitive information in a http …

Sunlitesri · portal_for_arcgisEPSS 0.33%via NVD
CVE-2026-69235Medium· 6.1
1mo ago

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s browser

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s browser. Users wo…

Sunlitesri · portal_for_arcgisEPSS 0.18%via NVD
CVE-2026-69234Medium· 6.1
1mo ago

There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS versions 11.5 and prior which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary …

There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS versions 11.5 and prior which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary …

Sunlitesri · portal_for_arcgisEPSS 0.24%via NVD
CVE-2026-69233Medium· 5.5
1mo ago

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s …

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s …

Sunlitesri · portal_for_arcgisEPSS 0.25%via NVD
CVE-2026-69232Medium· 5.5
1mo ago

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browse…

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browse…

Sunlitesri · portal_for_arcgisEPSS 0.24%via NVD
CVE-2026-69231Medium· 5.5
1mo ago

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browse…

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browse…

Sunlitesri · portal_for_arcgisEPSS 0.24%via NVD
CVE-2026-69236Medium· 6.1
1mo ago

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 12.1 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browse…

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 12.1 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browse…

Sunlitesri · portal_for_arcgisEPSS 0.18%via NVD
CVE-2026-2813Medium· 4.7
4mo ago

ArcGIS Server contains an input validation weakness in the login redirection workflow

ArcGIS Server contains an input validation weakness in the login redirection workflow. An Authenticated attacker could exploit this issue by sending a specially crafted request, Successful exploitation may result in the application redir…

Sunlitesri · arcgis_serverEPSS 0.30%via NVD
CVE-2026-2812Medium· 5.3
4mo ago

ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint

ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthenticated attacker could exploit this issue by sending a crafted request to the endpoint. Successful exploitation may re…

Sunlitesri · arcgis_serverEPSS 0.36%via NVD
esri vulnerabilities (CVEs) · VulnSea