{"id":"CVE-2025-10556","title":"A stored Cross-site Scripting (XSS) vulnerability affecting Specification Management in ENOVIA Specification Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code…","summary":"A stored Cross-site Scripting (XSS) vulnerability affecting Specification Management in ENOVIA Specification Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code…","severity":"high","cvss":8.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","cwe":["CWE-79"],"vendor":"3ds","product":"3dexperience_enovia","affected":["3dexperience_enovia >= r2023x, <= r2025x"],"published":"2025-10-13","updated":"2026-10-08","sourceUpdated":"2026-10-08T12:10:00.217","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-10556","references":[{"url":"https://www.3ds.com/trust-center/security/security-advisories/cve-2025-10556","label":"3DS.Information-Security@3ds.com"}],"tags":["nvd"],"epss":0.00201,"epssPercentile":0.09154,"ingestedAt":"2026-10-08T11:31:27.352Z","slug":"CVE-2025-10556","body":"## Overview\n\nA stored Cross-site Scripting (XSS) vulnerability affecting Specification Management in ENOVIA Specification Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.\n\n## Affected\n\n- `3dexperience_enovia >= r2023x, <= r2025x`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":47.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}