Vulnerability Description
There is an HTML injection issue in Esri ArcGIS Web AppBuilder developer edition versions prior to 2.30 that allows a remote, unauthenticated attacker to potentially entice a user to click a link that causes arbitrary HTML to render in a victim's browser. There is no evidence of JavaScript execution, which limits the impact. At the time of submission, ArcGIS Web App Builder developer edition is retired and unsupported. ArcGIS Web App Builder 2.30 is not susceptible to this vulnerability.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://support.esri.com/en-us/knowledge-base/deprecation-arcgis-web-appbuilder-
- https://www.mdronski.pl/2026/01/CVE-2025-67712-Proof-of-concept-and-technical-an
FAQ
What is CVE-2025-67712?
CVE-2025-67712 is a vulnerability with a CVSS score of 4.7 (MEDIUM). There is an HTML injection issue in Esri ArcGIS Web AppBuilder developer edition versions prior to 2.30 that allows a remote, unauthenticated attacker to potentially entice a user to click a link that...
How severe is CVE-2025-67712?
CVE-2025-67712 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-67712?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.