Jhy Jsoup vulnerabilities
2 known vulnerabilities affecting jhy/jsoup.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2022-36033MEDIUMCVSS 6.1fixed in 1.15.32022-08-29
CVE-2022-36033 [MEDIUM] CWE-79 CVE-2022-36033: jsoup is a Java HTML parser, built for HTML editing, cleaning, scraping, and cross-site scripting (X
jsoup is a Java HTML parser, built for HTML editing, cleaning, scraping, and cross-site scripting (XSS) safety. jsoup may incorrectly sanitize HTML including `javascript:` URL expressions, which could allow XSS attacks when a reader subsequently clicks that link. If the non-default `SafeList.preserveRelativeLinks` option is enabled, HTML including `j
cvelistv5nvd
CVE-2021-37714HIGHCVSS 7.5fixed in 1.14.22021-08-18
CVE-2021-37714 [HIGH] CWE-248 CVE-2021-37714: jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse u
jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on user supplied input, an attacker may supply content that causes the parser to get stuck (loop indefinitely until cancelled), to complete more slowly than usual, or to throw a
cvelistv5nvd