CVE-2025-0595: Dassault Systèmes 3dswymer

High severity, CVSS 8.7. EPSS: 0.3% chance of exploitation in the next 30 days.

A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

Affected products

  • Dassault Systèmes 3dswymer: from 3DEXPERIENCE R2022x Golden, up to and including 3DEXPERIENCE R2022x.FP.CFA.2433; from 3DEXPERIENCE R2023x Golden, up to and including 3DEXPERIENCE R2023x.FP.CFA.2428; from 3DEXPERIENCE R2024x Golden, up to and including 3DEXPERIENCE R2024x.FP.CFA.2432

Published 2025-03-17. Last modified 2026-06-17.