CVE-2013-6780
Yahoo Yui - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in uploader.swf in the Uploader component in Yahoo! YUI 2.5.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via the allowedDomain parameter.
References (4)
Scores
EPSS
0.0078
EPSS Percentile
73.4%
Details
CWE
CWE-79
Status
published
Products (10)
yahoo/yui
yahoo/yui
yahoo/yui
yahoo/yui
yahoo/yui
yahoo/yui
yahoo/yui
yahoo/yui
yahoo/yui
n/a/n/a
Published
Nov 13, 2013
Tracked Since
Feb 18, 2026