---
id: CVE-2025-12956
title: >-
  A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA
  Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through
  Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script
  code in user's bro…
summary: >-
  A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA
  Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through
  Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script
  code in user's bro…
severity: high
cvss: 8.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'
cwe:
  - CWE-79
vendor: 3ds
product: 3dexperience_enovia
affected:
  - '3dexperience_enovia >= r2022x, <= r2025x'
published: '2025-12-08'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-12956'
references:
  - url: >-
      https://www.3ds.com/trust-center/security/security-advisories/cve-2025-12956
    label: 3DS.Information-Security@3ds.com
tags:
  - nvd
epss: 0.00188
epssPercentile: 0.07652
ingestedAt: '2026-10-07T20:46:46.754Z'
---

## Overview

A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.

## Affected

- `3dexperience_enovia >= r2022x, <= r2025x`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
