Vendorsxxyopennovel-plusany version
Vulnerabilities

xxyopen novel-plus any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

26CVEs
CVE-2025-45890
Directory Traversal vulnerability in novel plus before v.5.1.0 allows a remote attacker to execute arbitrary code via the filePath parameter
Published 2025-06-20 · Analyzed
9.8EPSS 0.016
CVE-2021-42967
Unrestricted file upload in /novel-admin/src/main/java/com/java2nb/common/controller/FileController.java in novel-plus all versions allows allows an attacker to upload malicious JSP files.
Published 2022-05-13 · Modified
9.8EPSS 0.011
CVE-2025-4019
20120630 Novel-Plus GeneratorController.java genCode missing authentication
Published 2025-04-28 · Analyzed
9.8EPSS 0.007
CVE-2024-24026
An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions at com.java2nb.system.controller.SysUserController: uploadImg(). An attacker can pass in specially crafted filename parameter to perform arbitrary File download.
Published 2024-02-08 · Modified
9.8EPSS 0.007
CVE-2024-24024
An arbitrary File download vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileController: fileDownload(). An attacker can pass in specially crafted filePath and fieName parameters to perform arbitrary File download.
Published 2024-02-08 · Modified
9.8EPSS 0.007
CVE-2024-24025
An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileController: upload(). An attacker can pass in specially crafted filename parameter to perform arbitrary File download.
Published 2024-02-08 · Modified
9.8EPSS 0.007
CVE-2024-24017
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /common/dict/list
Published 2024-02-08 · Modified
9.8EPSS 0.006
CVE-2024-24014
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /novel/author/list
Published 2024-02-08 · Modified
9.8EPSS 0.006
CVE-2024-24021
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, limit, and sort parameters to perform SQL injection via /novel/userFeedback/list.
Published 2024-02-08 · Modified
9.8EPSS 0.006
CVE-2024-24023
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, limit, and sort parameters to perform SQL injection via /novel/bookContent/list.
Published 2024-02-08 · Modified
9.8EPSS 0.006
CVE-2024-24015
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL via /sys/user/exit
Published 2024-02-06 · Modified
9.8EPSS 0.006
CVE-2024-24018
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL injection via /system/dataPerm/list
Published 2024-02-08 · Modified
9.8EPSS 0.006
CVE-2024-24013
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /novel/pay/list
Published 2024-02-06 · Modified
9.8EPSS 0.006
CVE-2024-24019
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL injection via /system/roleDataPerm/list
Published 2024-02-07 · Modified
9.8EPSS 0.006
CVE-2025-4016
20120630 Novel-Plus LogController.java deleteIndex improper authorization
Published 2025-04-28 · Analyzed
9.1EPSS 0.005
CVE-2025-6535
xxyopen/201206030 novel-plus User Management Module UserMapper.xml list sql injection
Published 2025-06-24 · Analyzed
8.8EPSS 0.005
CVE-2025-4018
20120630 Novel-Plus CrawlController.java addCrawlSource missing authentication
Published 2025-04-28 · Analyzed
7.5EPSS 0.008
CVE-2025-4015
20120630 Novel-Plus SessionController.java list missing authentication
Published 2025-04-28 · Analyzed
7.5EPSS 0.008
CVE-2024-33383
Arbitrary File Read vulnerability in novel-plus 4.3.0 and before allows a remote attacker to obtain sensitive information via a crafted GET request using the filePath parameter.
Published 2024-04-30 · Analyzed
7.5EPSS 0.007
CVE-2025-6534
xxyopen/201206030 novel-plus File FileController.java remove resource injection
Published 2025-06-24 · Analyzed
6.8EPSS 0.005
CVE-2025-4017
20120630 Novel-Plus LogController.java list improper authorization
Published 2025-04-28 · Analyzed
6.5EPSS 0.006
CVE-2025-26182
An issue in xxyopen novel plus v.4.4.0 and before allows a remote attacker to execute arbitrary code via the PageController.java file
Published 2025-03-04 · Analyzed
6.5EPSS 0.005
CVE-2025-6533
xxyopen/201206030 novel-plus CATCHA LoginController.java ajaxLogin authentication replay
Published 2025-06-24 · Analyzed
5.9EPSS 0.006
CVE-2023-7166
Novel-Plus HTTP POST Request updateUserInfo cross site scripting
Published 2023-12-29 · Modified
5.4EPSS 0.005
CVE-2025-60298
Novel-Plus up to 5.2.4 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the /author/updateIndexName endpoint. This vulnerability allows authenticated attackers to inject malicious JavaScript code through the indexName parameter, which gets stored in the database and executed when other users view the affected book chapter.
Published 2025-10-08 · Analyzed
5.4EPSS 0.003
CVE-2023-7171
Novel-Plus Friendly Link FriendLinkController.java cross site scripting
Published 2023-12-29 · Modified
4.8EPSS 0.005