Vendorsxxyopennovel-plus3.6.1
Vulnerabilities

xxyopen novel-plus 3.6.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2021-41921
novel-plus V3.6.1 allows unrestricted file uploads. Unrestricted file suffixes and contents can lead to server attacks and arbitrary code execution.
Published 2022-04-28 · Modified
9.8EPSS 0.017
CVE-2022-35121
Novel-Plus v3.6.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /service/impl/BookServiceImpl.java.
Published 2022-08-17 · Modified
9.8EPSS 0.009