CVE-2025-67710: Esri Arcgis Server
Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.
There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.
Affected products
- Esri Arcgis Server: up to and including 11.5
Published 2025-12-31. Last modified 2026-09-23.