Jsoup is a widely used HTML parser and scraper library for Java that processes untrusted web content, with its vulnerability exposure centered on input-handling flaws in HTML parsing and sanitization. The recurring weakness classes—cross-site scripting variants, infinite loops, and uncaught exceptions—reflect the complexity of parsing and neutralizing malicious markup while maintaining functional HTML output. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jsoup over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-37714HIGH jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on u | Aug 18, 2021 | 7.5 | 30 | NO | NO |
CVE-2022-36033MEDIUM jsoup is a Java HTML parser, built for HTML editing, cleaning, scraping, and cross-site scripting (XSS) safety. jsoup may incorrectly sanitize HTML including `javascript:` URL expr | Aug 29, 2022 | 6.1 | 21 | NO | NO |
CVE-2015-6748MEDIUM Cross-site scripting (XSS) vulnerability in jsoup before 1.8.3. | Sep 25, 2017 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jsoup.
Media articles that mention a CVE ID that affects a product developed by Jsoup — matched by CVE ID, not by vendor name.