jsoup records
3 published records for vendor jsoup.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-248 Uncaught Exception1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
32Monitor | CVE-2021-37714No exploit | Crafted input may cause the jsoup HTML and XML parser to get stuck, timeout, or throw unchecked exceptionsjsoup · jsoup · CWE-248 | High7.5 | — | 6.7% | Aug 18, 2021 |
25Monitor | CVE-2015-6748Proof of concept | Cross-site scripting (XSS) vulnerability in jsoup before 1.8.3.jsoup · jsoup · CWE-79 | Medium6.1 | — | 2.2% | Sep 25, 2017 |
24Monitor | CVE-2022-36033No exploit | jsoup may not sanitize Cross-Site Scripting (XSS) attempts if SafeList.preserveRelativeLinks is enabledjsoup · jsoup · CWE-79 | Medium6.1 | — | 1.5% | Aug 29, 2022 |
- CVE-2021-3771432Monitor
Crafted input may cause the jsoup HTML and XML parser to get stuck, timeout, or throw unchecked exceptions
HighCVSS 7.5No exploitEPSS 7%jsoup · jsoupAug 18, 2021
- CVE-2015-674825Monitor
Cross-site scripting (XSS) vulnerability in jsoup before 1.8.3.
MediumCVSS 6.1Proof of conceptEPSS 2%jsoup · jsoupSep 25, 2017
- CVE-2022-3603324Monitor
jsoup may not sanitize Cross-Site Scripting (XSS) attempts if SafeList.preserveRelativeLinks is enabled
MediumCVSS 6.1No exploitEPSS 2%jsoup · jsoupAug 29, 2022