Vendorsxxyopennovel-plus3.6.2
Vulnerabilities

xxyopen novel-plus 3.6.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2022-36672
Novel-Plus v3.6.2 was discovered to contain a hard-coded JWT key located in the project config file. This vulnerability allows attackers to create a custom user session.
Published 2022-09-01 · Modified
9.8EPSS 0.013
CVE-2023-1594
novel-plus list MenuService sql injection
Published 2023-03-23 · Modified
9.8EPSS 0.010
CVE-2023-30058
novel-plus 3.6.2 is vulnerable to SQL Injection.
Published 2023-09-11 · Modified
9.8EPSS 0.010
CVE-2023-1606
novel-plus DictController.java sql injection
Published 2023-03-23 · Modified
9.8EPSS 0.009
CVE-2023-37847
novel-plus v3.6.2 was discovered to contain a SQL injection vulnerability.
Published 2023-08-14 · Modified
9.8EPSS 0.007
CVE-2023-2039
novel-plus sql injection
Published 2023-04-14 · Modified
8.8EPSS 0.008
CVE-2023-2041
novel-plus sql injection
Published 2023-04-14 · Modified
8.8EPSS 0.008
CVE-2023-2040
novel-plus sql injection
Published 2023-04-14 · Modified
8.8EPSS 0.007
CVE-2023-1607
novel-plus list sql injection
Published 2023-03-23 · Modified
8.8EPSS 0.007
CVE-2022-36671
Novel-Plus v3.6.2 was discovered to contain an arbitrary file download vulnerability via the background file download API.
Published 2022-09-01 · Modified
7.5EPSS 0.005
CVE-2023-1595
novel-plus list sql injection
Published 2023-03-23 · Modified
7.2EPSS 0.009