CVE-2025-35060: Newforma Project Center

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Newforma Info Exchange (NIX) provides a 'Send a File Transfer' feature that allows a remote, authenticated attacker to upload SVG files that contain JavaScript or other content that may be executed or rendered by a web browser using a mobile user agent.

Affected products

  • Newforma Project Center: before 2024.1 (fixed in 2024.1)

Published 2025-10-09. Last modified 2026-10-08.