Vendorsxxyopennovel-plusall versions
Vulnerabilities

xxyopen novel-plus

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

50CVEs
CVE-2023-41443
SQL injection vulnerability in Novel-Plus v.4.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /sys/menu/list.
Published 2023-09-18 · Modified
7.2EPSS 0.013
CVE-2023-1595
novel-plus list sql injection
Published 2023-03-23 · Modified
7.2EPSS 0.009
CVE-2025-6534
xxyopen/201206030 novel-plus File FileController.java remove resource injection
Published 2025-06-24 · Analyzed
6.8EPSS 0.004
CVE-2025-4017
20120630 Novel-Plus LogController.java list improper authorization
Published 2025-04-28 · Analyzed
6.5EPSS 0.006
CVE-2025-26182
An issue in xxyopen novel plus v.4.4.0 and before allows a remote attacker to execute arbitrary code via the PageController.java file
Published 2025-03-04 · Analyzed
6.5EPSS 0.005
CVE-2025-6533
xxyopen/201206030 novel-plus CATCHA LoginController.java ajaxLogin authentication replay
Published 2025-06-24 · Analyzed
5.9EPSS 0.005
CVE-2023-7166
Novel-Plus HTTP POST Request updateUserInfo cross site scripting
Published 2023-12-29 · Modified
5.4EPSS 0.005
CVE-2025-60298
Novel-Plus up to 5.2.4 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the /author/updateIndexName endpoint. This vulnerability allows authenticated attackers to inject malicious JavaScript code through the indexName parameter, which gets stored in the database and executed when other users view the affected book chapter.
Published 2025-10-08 · Analyzed
5.4EPSS 0.003
CVE-2025-60299
Novel-Plus with 5.2.0 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the /book/addCommentReply endpoint. An authenticated user can inject malicious JavaScript through the replyContent parameter when replying to a book comment. The payload is stored in the database and is executed in other users’ browsers when they view the affected comment thread.
Published 2025-10-08 · Analyzed
5.4EPSS 0.002
CVE-2023-7171
Novel-Plus Friendly Link FriendLinkController.java cross site scripting
Published 2023-12-29 · Modified
4.8EPSS 0.005
← Prev2 / 2