CVE-2010-4207
Yahoo Yui - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.8.1, as used in Bugzilla, Moodle, and other products, allows remote attackers to inject arbitrary web script or HTML via vectors related to charts/assets/charts.swf.
References (15)
Scores
EPSS
0.0293
EPSS Percentile
86.3%
Classification
CWE
CWE-79
Status
published
Affected Products (9)
yahoo/yui
yahoo/yui
yahoo/yui
yahoo/yui
yahoo/yui
yahoo/yui
yahoo/yui
yahoo/yui
n/a/n/a
Timeline
Published
Nov 07, 2010
Tracked Since
Feb 18, 2026