CVE-2025-67710: Stored XSS vulnerability in ArcGIS Server
Published Dec 31, 2025
·Updated
There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.
Affected Software
4 affected components
Esri ArcGIS Server<11.4
All of the following
Esri ArcGIS Server<=11.5
Any of the following
Linux Linux kernel
Microsoft Windows
Remediation
Event History
Dec 31, 2025
CVE Published
via MITRE·10:18 PM
Data Sourced
via MITRE·10:18 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-67710?
The severity of CVE-2025-67710 is considered high due to its potential for remote exploitation.
2
How do I fix CVE-2025-67710?
To fix CVE-2025-67710, upgrade to a patched version of Esri ArcGIS Server later than 11.4.
3
Who is affected by CVE-2025-67710?
CVE-2025-67710 affects users of Esri ArcGIS Server version 11.4 and earlier on both Windows and Linux.
4
What type of vulnerability is CVE-2025-67710?
CVE-2025-67710 is classified as a stored cross-site scripting (XSS) vulnerability.
5
Can CVE-2025-67710 be exploited by an unauthenticated attacker?
Yes, CVE-2025-67710 can be exploited by an unauthenticated remote attacker under certain configurations.