jsoup is a Java library that simplifies working with real-world HTML and XML. It offers an easy-to-use API for URL fetching, data parsing, extraction, and manipulation using DOM API methods, CSS, and xpath selectors. jsoup implements the WHATWG HTML5 specification, and parses HTML to the same DOM as modern browsers.
97%
Total Score
92
97
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-499637 New jsoup is vulnerable to Cross-Site Scripting (XSS) in versions 1.14.3 - 1.22.2. | 1.14.3 - 1.22.2 | Medium |
AIKIDO-2025-10401 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. jsoup is vulnerable to Cross-site Scripting (XSS) in versions 1.12.2 - 1.21.0. | 1.12.2 - 1.21.0 | Medium |
CVE-2022-36033 org.jsoup:jsoup is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.15.3. | 0.0.0 - 1.15.3 | Medium |
CVE-2015-6748 org.jsoup:jsoup is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 1.6.0 - 1.8.2. | 1.6.0 - 1.8.2 | Medium |
CVE-2021-37714 org.jsoup:jsoup is vulnerable to Uncaught Exception in versions 0.0.0 - 1.14.2. | 0.0.0 - 1.14.2 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
com.google.re2j:re2j Version 1.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant