Dassault Systèmes disclosed two high-severity stored cross-site scripting vulnerabilities, CVE-2025-10551 and CVE-2025-10553, affecting Document Management in ENOVIA Collaborative Industry Innovator and Factory Resource Management in DELMIA Factory Resource Manager. Both flaws impact 3DEXPERIENCE releases from R2023x through R2025x and could let an authenticated attacker inject malicious content that executes arbitrary script code in another user's browser session.
The vulnerabilities are classified as CWE-79 and carry the same CVSS v3.1 vector, AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N, indicating network-based exploitation with low attack complexity, required low privileges, and user interaction. Vendor references point to Dassault Systèmes security advisories, and the impact profile highlights potential compromise of confidentiality and integrity within affected browser sessions.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
On March 31, 2026, CVE entries were published documenting CVE-2025-10551 and CVE-2025-10553, including CVSS v3.1 scoring, CWE-79 classification, and references to Dassault Systèmes security advisories. Both vulnerabilities could allow arbitrary script execution in a user's browser session.
Dassault Systèmes received a report of CVE-2025-10553 on March 31, 2026. The issue is a stored XSS vulnerability in Factory Resource Management in DELMIA Factory Resource Manager affecting 3DEXPERIENCE releases R2023x through R2025x.
Dassault Systèmes received a report of CVE-2025-10551 on March 31, 2026. The flaw is a stored XSS vulnerability in Document Management in ENOVIA Collaborative Industry Innovator affecting 3DEXPERIENCE releases R2023x through R2025x.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.