CVE-2025-10551Disclosure(3ds / 3dexperience)

LOWCVSS 5.4 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A Stored Cross-site Scripting (XSS) vulnerability affecting Document Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 3dexperience

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
3dexperience

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-31: 3Technical Details · 2026-03-31: 303-31
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2025-10551 A Stored Cross-site Scripting (XSS) vulnerability affecting Document Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2023x through Re… https://www.cve.org/CVERecord?id=CVE-2025-10551

    Post summary

    The text announces a stored XSS vulnerability (CVE‑2025‑10551) in ENOVIA Collaborative Industry Innovator, providing basic technical details but no PoC or patch information.

    0000076
    56.9K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2025-10551: HIGH] Critical vulnerability in Document Management of ENOVIA Collaborative Industry Innovator (Release 3DEXPERIENCE R2023x-R2025x) enables Stored XSS attack, letting hackers run code in use...#cve,CVE-2025-10551,#cybersecurity https://cvefind.com/CVE-2025-10551

    Post summary

    The post announces a high‑severity stored XSS vulnerability (CVE‑2025‑10551) in ENOVIA's Document Management, noting potential for malicious code execution, but provides no exploit, PoC, or mitigation details.

    0000056
    617 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-10551 - High A Stored Cross-site Scripting (XSS) vulnerability affecting Document Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x... https://www.thehackerwire.com/vulnerability/CVE-2025-10551/ https://t.co/IKEZHZ0KfX

    Post summary

    A newly disclosed stored XSS vulnerability (CVE‑2025‑10551) in ENOVIA Collaborative Industry Innovator affecting specified releases, with no PoC, exploit, or patch information included.

    00000170
    163 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OS3ds3dexperience---

Explore more