CVE-2015-6748Medium· 6.1▾ TwilightPoC availableCross-site scripting (XSS) vulnerability in jsoup before 1.8.3.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 33.6 · likelihood 0.4 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
2.2%
1 GitHub repo (last check)
Cross-site scripting (XSS) vulnerability in jsoup before 1.8.3.
jsoup >= 1.6.0, < 1.8.3debian_linux = 8.0Upgrade past the affected range:
jsoup 1.8.3Connected by shared product, vendor, weakness, or advisory.
CVE-2021-37714High· 7.5jsoup is a Java library for working with HTML
CVE-2021-41184Medium· 6.5jQuery-UI is the official jQuery user interface library
CVE-2021-41182Medium· 6.5jQuery-UI is the official jQuery user interface library
CVE-2020-3580Medium· 6.1Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting …
CVE-2026-71497Medium· 4.7jsoup is a Java library for working with real-world HTML
CVE-2021-41164High· 8.2CKEditor4 is an open source WYSIWYG HTML editor