CVE-2025-55104
MEDIUMArcGIS HUB/ArcGIS Enterprise Sites - XSS
Title source: llmDescription
A stored cross-site scripting (XSS) vulnerability exists ArcGIS HUB and ArcGIS Enterprise Sites which allows an authenticated user with the ability to create or edit a site to add and store an XSS payload. If this stored XSS payload is triggered by any user attacker supplied JavaScript may execute in the victim's browser.
Scores
CVSS v3
4.8
EPSS
0.0002
EPSS Percentile
5.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-79
Status
published
Affected Products (1)
esri/portal_for_arcgis
< 11.4
Timeline
Published
Aug 21, 2025
Tracked Since
Feb 18, 2026