There is a stored cross site scripting issue in Esri...
Moderate severity
Unreviewed
Published
Jan 1, 2026
to the GitHub Advisory Database
•
Updated Jan 1, 2026
Description
Published by the National Vulnerability Database
Dec 31, 2025
Published to the GitHub Advisory Database
Jan 1, 2026
Last updated
Jan 1, 2026
There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.
References