The Cross Domain Local Storage Project maintains a single specialized component for cross-domain data access, where the observed vulnerability pattern centers on input handling and trust-boundary weaknesses including improper input validation, resource exposure across security spheres, and open-redirect flaws. This reflects the inherent complexity of managing data sharing and navigation across domain boundaries; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cross Domain Local Storage Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-11610HIGH An issue was discovered in xdLocalStorage through 2.0.5. The postData() function in xdLocalStoragePostMessageApi.js specifies the wildcard (*) as the targetOrigin when calling the | Apr 7, 2020 | 8.8 | 22 | NO | NO |
CVE-2015-9545HIGH An issue was discovered in xdLocalStorage through 2.0.5. The receiveMessage() function in xdLocalStorage.js does not implement any validation of the origin of web messages. Remote | Apr 7, 2020 | 7.1 | 19 | NO | NO |
CVE-2015-9544HIGH An issue was discovered in xdLocalStorage through 2.0.5. The receiveMessage() function in xdLocalStoragePostMessageApi.js does not implement any validation of the origin of web mes | Apr 7, 2020 | 7.1 | 19 | NO | NO |
CVE-2020-11611MEDIUM An issue was discovered in xdLocalStorage through 2.0.5. The buildMessage() function in xdLocalStorage.js specifies the wildcard (*) as the targetOrigin when calling the postMessag | Apr 7, 2020 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cross Domain Local Storage Project.
Media articles that mention a CVE ID that affects a product developed by Cross Domain Local Storage Project — matched by CVE ID, not by vendor name.