Since Yahoo is no longer updating the project (per this announcement: https://yahooeng.tumblr.com/post/96098168666/important-announcement-regarding-yui), I've decided to disclose the vulnerabilities here:
The application has a lot of reflected XSS vulnerabilities in pretty much most files. A sample of the vulnerable files along with the exploit can be found here: