Easyxdm is a niche cross-domain messaging library designed to facilitate secure communication across iframe and window boundaries in web applications. The observed vulnerability exposure centers on its core function and recurs through cross-site scripting weaknesses in input neutralization, reflecting the inherent challenges of safely handling cross-origin message passing. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Easyxdm over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-5212MEDIUM Cross-site Scripting (XSS) in EasyXDM before 2.4.18 allows remote attackers to inject arbitrary web script or html via the easyxdm.swf file. | Feb 14, 2020 | 6.1 | 19 | NO | NO |
CVE-2023-27739MEDIUM easyXDM 2.5 allows XSS via the xdm_e parameter. | Jan 8, 2024 | 6.1 | 18 | NO | NO |
CVE-2014-1403MEDIUM Cross-site scripting (XSS) vulnerability in name.html in easyXDM before 2.4.19 allows remote attackers to inject arbitrary web script or HTML via the location.hash value. | Feb 5, 2014 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Easyxdm.
Media articles that mention a CVE ID that affects a product developed by Easyxdm — matched by CVE ID, not by vendor name.