cbcvebase.

Xxyopen Novel-Plus vulnerabilities

48 known vulnerabilities affecting xxyopen/novel-plus.

Total CVEs
48
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL28HIGH12MEDIUM8

Vulnerabilities

Page 3 of 3
CVE-2022-24568P3CRITICALCVSS 9.8v3.6.02022-02-10
CVE-2022-24568 [CRITICAL] CWE-918 CVE-2022-24568: Novel-plus v3.6.0 was discovered to be vulnerable to Server-Side Request Forgery (SSRF) via user-sup Novel-plus v3.6.0 was discovered to be vulnerable to Server-Side Request Forgery (SSRF) via user-supplied crafted input.
nvd
CVE-2023-41443P3HIGHCVSS 7.2v4.1.02023-09-18
CVE-2023-41443 [HIGH] CWE-89 CVE-2023-41443: SQL injection vulnerability in Novel-Plus v.4.1.0 allows a remote attacker to execute arbitrary code SQL injection vulnerability in Novel-Plus v.4.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /sys/menu/list.
nvd
CVE-2025-26182P3MEDIUMCVSS 6.5≤ 4.4.02025-03-04
CVE-2025-26182 [MEDIUM] CWE-94 CVE-2025-26182: An issue in xxyopen novel plus v.4.4.0 and before allows a remote attacker to execute arbitrary code An issue in xxyopen novel plus v.4.4.0 and before allows a remote attacker to execute arbitrary code via the PageController.java file
nvd
CVE-2025-6533P3MEDIUMCVSS 5.9≤ 5.1.3v5.1.0+3 more2025-06-24
CVE-2025-6533 [MEDIUM] CWE-287 CVE-2025-6533: A vulnerability, which was classified as critical, has been found in xxyopen/201206030 novel-plus up A vulnerability, which was classified as critical, has been found in xxyopen/201206030 novel-plus up to 5.1.3. Affected by this issue is the function ajaxLogin of the file novel-admin/src/main/java/com/java2nb/system/controller/LoginController.java of the component CATCHA Handler. The manipulation leads to authentication bypass by capture-replay. The
nvd
CVE-2023-7166P4MEDIUMCVSS 5.4≤ 4.2.0v4.0+2 more2023-12-29
CVE-2023-7166 [MEDIUM] CWE-79 CVE-2023-7166: A vulnerability classified as problematic has been found in Novel-Plus up to 4.2.0. This affects an A vulnerability classified as problematic has been found in Novel-Plus up to 4.2.0. This affects an unknown part of the file /user/updateUserInfo of the component HTTP POST Request Handler. The manipulation of the argument nickName leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public
nvd
CVE-2025-60298P4MEDIUMCVSS 5.4≤ 5.2.42025-10-08
CVE-2025-60298 [MEDIUM] CWE-79 CVE-2025-60298: Novel-Plus up to 5.2.4 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability v Novel-Plus up to 5.2.4 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the /author/updateIndexName endpoint. This vulnerability allows authenticated attackers to inject malicious JavaScript code through the indexName parameter, which gets stored in the database and executed when other users view the affected book chapt
nvd
CVE-2025-60299P4MEDIUMCVSS 5.4v5.2.02025-10-08
CVE-2025-60299 [MEDIUM] CWE-79 CVE-2025-60299: Novel-Plus with 5.2.0 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability vi Novel-Plus with 5.2.0 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the /book/addCommentReply endpoint. An authenticated user can inject malicious JavaScript through the replyContent parameter when replying to a book comment. The payload is stored in the database and is executed in other users’ browsers when they vie
nvd
CVE-2023-7171P4MEDIUMCVSS 4.8≤ 4.2.0v4.0+2 more2023-12-29
CVE-2023-7171 [MEDIUM] CWE-79 CVE-2023-7171: A vulnerability was found in Novel-Plus up to 4.2.0. It has been declared as problematic. Affected b A vulnerability was found in Novel-Plus up to 4.2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file novel-admin/src/main/java/com/java2nb/novel/controller/FriendLinkController.java of the component Friendly Link Handler. The manipulation leads to cross site scripting. The attack can be launch
nvd
Xxyopen Novel-Plus vulnerabilities | cvebase