org.jsoup:jsoup
Maven4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.jsoup:jsouppage 1 of 1
- CVE-2015-6748MEDIUMCVSS 6.1EG 6.1✓ Fixed in 1.8.32017-09-25
vulnerable: 1.6.0 ... 1.8.2 (9 versions)
Cross-site scripting (XSS) vulnerability in jsoup before 1.8.3.
- CVE-2021-37714HIGHCVSS 7.5EG 7.5✓ Fixed in 1.14.22021-08-18
vulnerable: 0.2.1b ... 1.9.2 (35 versions)
jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on user supplied input, an attacker may supply content that cau…
- CVE-2022-36033MEDIUMCVSS 6.1EG 6.1✓ Fixed in 1.15.32022-08-29
vulnerable: 0.2.1b ... 1.9.2 (39 versions)
jsoup is a Java HTML parser, built for HTML editing, cleaning, scraping, and cross-site scripting (XSS) safety. jsoup may incorrectly sanitize HTML including `javascript:` URL expressions, which could allow XSS attacks when a reader subseq…
- CVE-2026-71497MEDIUMCVSS 4.7EG 4.7✓ Fixed in 1.23.12026-08-06
vulnerable: 1.14.3 ... 1.22.2 (18 versions)
jsoup is a Java library for working with real-world HTML. From 1.14.3 until 1.23.1, jsoup's HTML parser could incorrectly handle a malformed tag name ending in a control character, causing the tag to acquire the parsing behavior of a diffe…
Check whether org.jsoup:jsoup is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.jsoup:jsoup CVEs against the assets you own.
Start Free Scan →