CVE-2026-69238
- EPSS 0.14%
- Veröffentlicht 21.08.2026 21:17:04
- Zuletzt bearbeitet 11.09.2026 20:17:12
There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.5 and prior that allows a remote, highly priviliged attacker to insert arbitrary HTML into the Portal for ArcGIS Home application. Users working with ArcGIS Enterprise 11....
CVE-2026-69237
- EPSS 0.2%
- Veröffentlicht 21.08.2026 21:17:04
- Zuletzt bearbeitet 11.09.2026 20:18:01
There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.3 and prior that allows a remote attacker with administrative privileges to insert arbitrary HTML into an administrative API. Users working with ArcGIS Enterprise 11.1, an...
CVE-2026-69236
- EPSS 0.18%
- Veröffentlicht 21.08.2026 21:17:04
- Zuletzt bearbeitet 11.09.2026 16:26:18
There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 12.1 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browser. Users work...
CVE-2026-69235
- EPSS 0.18%
- Veröffentlicht 21.08.2026 21:17:04
- Zuletzt bearbeitet 11.09.2026 16:50:00
There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s browser. Users working with Ar...
CVE-2026-69234
- EPSS 0.24%
- Veröffentlicht 21.08.2026 21:17:04
- Zuletzt bearbeitet 11.09.2026 17:02:00
There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS versions 11.5 and prior which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript co...
CVE-2026-69233
- EPSS 0.25%
- Veröffentlicht 21.08.2026 21:17:04
- Zuletzt bearbeitet 11.09.2026 17:03:45
There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s browser. User...
CVE-2026-69228
- EPSS 0.34%
- Veröffentlicht 21.08.2026 21:17:03
- Zuletzt bearbeitet 11.09.2026 17:51:42
There is a missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that may allow a remote, unauthenticated attacker to access a specific resource (not user content) that should only be accessible by authenticated users...
CVE-2026-69224
- EPSS 0.33%
- Veröffentlicht 21.08.2026 21:17:03
- Zuletzt bearbeitet 11.09.2026 17:59:56
There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 12.0 and earlier that may under difficult to reproduce circumstances allow a remote, unauthenticated attacker to reflect sensitive information in a http response body...
CVE-2026-69225
- EPSS 0.33%
- Veröffentlicht 21.08.2026 21:17:03
- Zuletzt bearbeitet 11.09.2026 17:58:14
There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 11.5 through 12.0 and earlier that may allow a remote, unauthenticated attacker to reflect sensitive information in a http response body.
CVE-2026-69229
- EPSS 0.22%
- Veröffentlicht 21.08.2026 21:17:03
- Zuletzt bearbeitet 11.09.2026 17:50:09
There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that allows a remote, authenticated attacker to insert arbitrary HTML into the Portal for ArcGIS Home application. Users working with ArcGIS Enterprise 11.1, 1...