CVE-2025-67704: Stored XSS vulnerability in ArcGIS Server.
Published Dec 31, 2025
·Updated
There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.
Affected Software
4 affected components
Esri ArcGIS Server<=11.4
All of the following
Esri ArcGIS Server<=11.5
Any of the following
Linux Linux kernel
Microsoft Windows
Remediation
Event History
Dec 31, 2025
CVE Published
via MITRE·10:14 PM
Data Sourced
via MITRE·10:14 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-67704?
CVE-2025-67704 is classified as a medium severity vulnerability.
2
How do I fix CVE-2025-67704?
To fix CVE-2025-67704, upgrade to ArcGIS Server version 11.5 or later where the vulnerability is addressed.
3
What are the potential impacts of CVE-2025-67704?
An attacker exploiting CVE-2025-67704 could execute arbitrary code in the context of a victim's web browser.
4
Which versions of Esri ArcGIS Server are affected by CVE-2025-67704?
ArcGIS Server versions 11.4 and earlier are affected by CVE-2025-67704.
5
Is authentication required to exploit CVE-2025-67704?
No, CVE-2025-67704 can be exploited by unauthenticated remote attackers.