Vulnerability Database

309,364

Total vulnerabilities in the database

CVE-2025-4985

A stored Cross-site Scripting (XSS) vulnerability affecting Risk Management in Project Portfolio Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.

  • Published: May 30, 2025
  • Updated: Nov 16, 2025
  • CVE: CVE-2025-4985
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 8.7
  • AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N