Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

ArcGIS Server — Vulnerabilities & Security Advisories 56

All 56 CVE vulnerabilities found in ArcGIS Server, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security weaknesses associated with ArcGIS Server, focusing on various vulnerability classes and associated tags maintained by major vendors. The content compiled here encompasses a broad spectrum of security flaws, including remote code execution, cross-site scripting, and privilege escalation issues, covering historical records from the early 2000s through to the most recent disclosures. By presenting this data in a unified view, the page enables users to efficiently track vendor-specific advisories as they are published, providing a clear lineage of security updates and patches released over time. Additionally, it allows security professionals to deeply understand the characteristics of specific weakness classes by observing how they manifest across different versions of the software. Users can also look up the comprehensive vulnerability history of ArcGIS Server to identify trends, assess the impact of specific flaws on their infrastructure, and prioritize remediation efforts based on severity and availability. This resource is designed to support informed decision-making for system administrators and security analysts who rely on accurate, consolidated information to maintain the integrity and safety of their geospatial information systems without sifting through disparate sources.

Vendor: Esri

CVE IDTitleCVSSSeverityPublished
CVE-2026-2813 Unvalidated Redirect in ArcGIS Server 4.7 Medium2026-05-20
CVE-2026-2812 Improper Authentication issue in ArcGIS Server CWE-287 5.3 Medium2026-05-20
CVE-2025-67711 Reflected XSS vulnerability in ArcGIS Server. CWE-79 6.1 Medium2025-12-31
CVE-2025-67710 Stored XSS vulnerability in ArcGIS Server CWE-79 6.1 Medium2025-12-31
CVE-2025-67709 There is a cross site scripting issue in ArcGIS Server. CWE-79 6.1 Medium2025-12-31
CVE-2025-67708 Reflected cross-site scripting (XSS) vulnerability in ArcGIS Server. CWE-79 6.1 Medium2025-12-31
CVE-2025-67707 Unvalidated File Upload vulnerability in ArcGIS Server. CWE-434 5.6 Medium2025-12-31
CVE-2025-67706 Unvalidated File Upload vulnerability in ArcGIS Server. CWE-434 5.6 Medium2025-12-31
CVE-2025-67705 Reflected XSS vulnerability in ArcGIS Server. CWE-79 6.1 Medium2025-12-31
CVE-2025-67704 Stored XSS vulnerability in ArcGIS Server. CWE-79 6.1 Medium2025-12-31
CVE-2025-67703 Stored XSS vulnerability in ArcGIS Server. CWE-79 6.1 Medium2025-12-31
CVE-2025-57870 BUG-000179884 - There is a security vulnerability in ArcGIS Server Feature Services. CWE-89 10.0 Critical2025-10-22
CVE-2024-51966 Directory traversal vulnerability in ArcGIS Server CWE-22 4.9 Medium2025-03-03
CVE-2024-51963 Stored XSS in ArcGIS Server Manager CWE-79 4.8 Medium2025-03-03
CVE-2024-51962 SQL injection vulnerability in ArcGIS Server CWE-89 8.7 High2025-03-03
CVE-2024-51961 Local file inclusion (LFI) vulnerability in ArcGIS Server CWE-73 7.5 High2025-03-03
CVE-2024-51960 Stored XSS in ArcGIS Server Administrator Directory CWE-79 4.8 Medium2025-03-03
CVE-2024-51959 Stored XSS issue in Server Admin API CWE-79 4.8 Medium2025-03-03
CVE-2024-51958 Directory traversal vulnerability in the admin api for service thumbnails CWE-22 4.9 Medium2025-03-03
CVE-2024-51957 Stored XSS vulnerability in ArcGIS Rest Services Directory CWE-79 4.8 Medium2025-03-03
CVE-2024-51956 Stored XSS vulnerability in ArcGIS Server Administrator Directory CWE-79 4.8 Medium2025-03-03
CVE-2024-51954 Unauthorized access to secure services in ArcGIS Server CWE-284 8.5 High2025-03-03
CVE-2024-51953 Stored XSS in ArcGIS Server Rest services CWE-79 4.8 Medium2025-03-03
CVE-2024-51952 Stored XSS issue in ArcGIS Server CWE-79 4.8 Medium2025-03-03
CVE-2024-51951 Stored XSS in Server Admin API CWE-79 4.8 Medium2025-03-03
CVE-2024-51950 Stored XSS in Server Admin under Services > lifecycleinfos CWE-79 4.8 Medium2025-03-03
CVE-2024-51949 Stored XSS vulnerability in Rest Services under OGCFeature Service and Map Service CWE-79 4.8 Medium2025-03-03
CVE-2024-51948 Stored XSS vulnerability in Rest Services under Job ID CWE-79 4.8 Medium2025-03-03
CVE-2024-51947 Stored XSS vulnerability in Rest Services under Layer name CWE-79 4.8 Medium2025-03-03
CVE-2024-51946 Stored XSS in Rest Services Directory under Identify operation CWE-79 4.8 Medium2025-03-03

All 56 known CVE vulnerabilities affecting ArcGIS Server with full Chinese analysis, references, and POCs where available.