VYPR

Novel Plus

by Xxyopen

Source repositories

CVEs (50)

  • CVE-2025-60298MedOct 8, 2025
    risk 0.35cvss 5.4epss 0.00

    Novel-Plus up to 5.2.4 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the /author/updateIndexName endpoint. This vulnerability allows authenticated attackers to inject malicious JavaScript code through the indexName parameter, which gets stored…

  • CVE-2025-4018MedApr 28, 2025
    risk 0.35cvss 5.3epss 0.01

    A vulnerability, which was classified as critical, has been found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This issue affects the function addCrawlSource of the file novel-crawl/src/main/java/com/java2nb/novel/controller/CrawlController.java. The…

  • CVE-2025-4016MedApr 28, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability classified as critical has been found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This affects the function deleteIndex of the file novel-admin/src/main/java/com/java2nb/common/controller/LogController.java. The manipulation leads to…

  • CVE-2025-4015MedApr 28, 2025
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. It has been rated as critical. Affected by this issue is the function list of the file novel-system/src/main/java/com/java2nb/system/controller/SessionController.java. The…

  • CVE-2023-1607MedMar 23, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in novel-plus 3.6.2. It has been classified as critical. This affects an unknown part of the file /common/sysFile/list. The manipulation of the argument sort leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2023-1595MedMar 23, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability has been found in novel-plus 3.6.2 and classified as critical. Affected by this vulnerability is an unknown functionality of the file common/log/list. The manipulation of the argument sort leads to sql injection. The attack can be launched remotely. The exploit…

  • CVE-2025-4017MedApr 28, 2025
    risk 0.28cvss 4.3epss 0.01

    A vulnerability classified as problematic was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This vulnerability affects the function list of the file nnovel-admin/src/main/java/com/java2nb/common/controller/LogController.java. The manipulation leads…

  • CVE-2025-6534MedJun 24, 2025
    risk 0.27cvss 4.2epss 0.00

    A vulnerability, which was classified as problematic, was found in xxyopen/201206030 novel-plus up to 5.1.3. This affects the function remove of the file novel-admin/src/main/java/com/java2nb/common/controller/FileController.java of the component File Handler. The manipulation…

  • CVE-2023-7171LowDec 29, 2023
    risk 0.00cvss 2.4epss 0.01

    A vulnerability was found in Novel-Plus up to 4.2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file novel-admin/src/main/java/com/java2nb/novel/controller/FriendLinkController.java of the component Friendly Link…

  • CVE-2023-7166LowDec 29, 2023
    risk 0.00cvss 3.5epss 0.01

    A vulnerability classified as problematic has been found in Novel-Plus up to 4.2.0. This affects an unknown part of the file /user/updateUserInfo of the component HTTP POST Request Handler. The manipulation of the argument nickName leads to cross site scripting. It is possible…

Page 3 of 3