3dexperience
Vendor:
First CVE: May 19, 2023 · Active for 3 years
11
Total CVEs
More Total CVEs than 89% of tracked products
3.7
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 25% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact 3dexperience over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 19, 2023
3 years ago
Most Recent CVE
Mar 31, 2026
115 days ago
CVE Severity & Scoring
3dexperience11 CVEs
82%
9%
9%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (18.2%)
Unknown0 (0.0%)
Required9 (81.8%)
Privileges Required
Low7 (63.6%)
High0 (0.0%)
None4 (36.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-10559CRITICAL A Path Traversal vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows | Mar 31, 2026 | 9.1 | 29 | NO | NO |
CVE-2023-1997HIGH An OS Command Injection vulnerability exists in SIMULIA 3DOrchestrate from Release 3DEXPERIENCE R2021x through Release 3DEXPERIENCE R2023x. A specially crafted HTTP request can lea | Aug 28, 2023 | 8.8 | 26 | NO | NO |
CVE-2025-10553MEDIUM A Stored Cross-site Scripting (XSS) vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERI | Mar 31, 2026 | 5.4 | 22 | NO | NO |
CVE-2025-10551MEDIUM A Stored Cross-site Scripting (XSS) vulnerability affecting Document Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2023x through Release 3DEXPERI | Mar 31, 2026 | 5.4 | 22 | NO | NO |
CVE-2023-1996MEDIUM A reflected Cross-site Scripting (XSS) vulnerability in Release 3DEXPERIENCE R2018x through Release 3DEXPERIENCE R2023x allows an attacker to execute arbitrary script code. | May 19, 2023 | 6.1 | 20 | NO | NO |
CVE-2024-6378MEDIUM A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows a | Aug 20, 2024 | 5.4 | 19 | NO | NO |
CVE-2024-7939MEDIUM A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser | Sep 2, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-7938MEDIUM A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2024x allows an attacker to execu | Sep 2, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-7932MEDIUM A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's bro | Sep 2, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-6379MEDIUM A reflected Cross-site Scripting (XSS) vulnerability affecting 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary | Aug 20, 2024 | 6.1 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| r2024x | 3 | 5.4 | 0.3% | 0 | 0 |
| r2023x | 2 | 7.1 | 1.0% | 0 | 0 |
| r2022x | 1 | 8.8 | 1.7% | 0 | 0 |
| r2021x | 1 | 8.8 | 1.7% | 0 | 0 |