{"id":"CVE-2015-6748","title":"Cross-site scripting (XSS) vulnerability in jsoup before 1.8.3.","summary":"Cross-site scripting (XSS) vulnerability in jsoup before 1.8.3.","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"jsoup","product":"jsoup","affected":["jsoup >= 1.6.0, < 1.8.3","debian_linux = 8.0"],"patched":["jsoup 1.8.3"],"published":"2017-09-25","updated":"2026-10-08","sourceUpdated":"2026-10-08T22:16:37.610","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2015-6748","references":[{"url":"http://www.openwall.com/lists/oss-security/2015/08/28/5","label":"secalert@redhat.com"},{"url":"http://www.securityfocus.com/bid/76504","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1258310","label":"secalert@redhat.com"},{"url":"https://github.com/jhy/jsoup/pull/582","label":"secalert@redhat.com"},{"url":"https://hibernate.atlassian.net/browse/HV-1012","label":"secalert@redhat.com"},{"url":"https://issues.jboss.org/browse/WFLY-5223?_sscc=t","label":"secalert@redhat.com"},{"url":"https://lists.debian.org/debian-lts-announce/2020/01/msg00021.html","label":"secalert@redhat.com"},{"url":"http://www.openwall.com/lists/oss-security/2015/08/28/5","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/bid/76504","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1258310","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/jhy/jsoup/pull/582","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://hibernate.atlassian.net/browse/HV-1012","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://issues.jboss.org/browse/WFLY-5223?_sscc=t","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2020/01/msg00021.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.02195,"epssPercentile":0.81928,"exploits":{"github":1,"githubRepos":["https://github.com/epicosy/VUL4J-59"],"checkedAt":"2026-10-08T23:17:21.730Z"},"exploitAvailable":true,"ingestedAt":"2026-10-08T23:16:47.286Z","slug":"CVE-2015-6748","body":"## Overview\n\nCross-site scripting (XSS) vulnerability in jsoup before 1.8.3.\n\n## Affected\n\n- `jsoup >= 1.6.0, < 1.8.3`\n- `debian_linux = 8.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `jsoup 1.8.3`","depth":"twilight","depthScore":46,"depthScoreParts":{"impact":33.6,"likelihood":0.4,"exploitation":12,"ransomware":0},"changes":[]}