{"id":"CVE-2010-4183","aliases":["GHSA-3p68-m5qw-9g9w"],"url":"https://o3.security/vulnerability/CVE-2010-4183","summary":"HTML Purifier cross-site scripting (XSS) vulnerability","details":"Multiple cross-site scripting (XSS) vulnerabilities in HTML Purifier before 4.1.0, when Internet Explorer is used, allow remote attackers to inject arbitrary web script or HTML via a crafted (1) background-image, (2) background, or (3) font-family Cascading Style Sheets (CSS) property, a different vulnerability than CVE-2010-2479.","published":"2010-11-05T17:00:03Z","modified":"2026-04-10T03:41:28.655417Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"ezyang/htmlpurifier","fixedVersion":"4.1.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"http://htmlpurifier.org/news/2010/0915-4.2.0-released"},{"type":"WEB","url":"http://htmlpurifier.org/security/2010/css-quoting"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-04-10T03:41:28.655417Z"}}