VYPR
Vendor

Novel Plus

Products
1
CVEs
34
Across products
34
Status
Private

Products

1

Recent CVEs

34
View all 34 CVEs →
  • CVE-2024-25274CriFeb 20, 2024
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the component /sysFile/upload of Novel-Plus v4.3.0-RC1 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2024-24021CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, limit, and sort parameters to perform SQL injection via /novel/userFeedback/list.

  • CVE-2024-24017CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /common/dict/list

  • CVE-2024-24014CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /novel/author/list

  • CVE-2024-24026CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions at com.java2nb.system.controller.SysUserController: uploadImg(). An attacker can pass in specially crafted filename parameter to perform arbitrary File download.

  • CVE-2024-24024CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    An arbitrary File download vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileController: fileDownload(). An attacker can pass in specially crafted filePath and fieName parameters to perform arbitrary File download.

  • CVE-2024-24019CriFeb 7, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL injection via /system/roleDataPerm/list

  • CVE-2023-46981CriNov 5, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Novel-Plus v.4.2.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /common/log/list.

  • CVE-2023-30058CriSep 11, 2023
    risk 0.64cvss 9.8epss 0.01

    novel-plus 3.6.2 is vulnerable to SQL Injection.

  • CVE-2023-37847CriAug 14, 2023
    risk 0.64cvss 9.8epss 0.01

    novel-plus v3.6.2 was discovered to contain a SQL injection vulnerability.

  • CVE-2022-36672CriSep 1, 2022
    risk 0.64cvss 9.8epss 0.01

    Novel-Plus v3.6.2 was discovered to contain a hard-coded JWT key located in the project config file. This vulnerability allows attackers to create a custom user session.

  • CVE-2022-35121CriAug 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Novel-Plus v3.6.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /service/impl/BookServiceImpl.java.

  • CVE-2021-42967CriMay 13, 2022
    risk 0.64cvss 9.8epss 0.01

    Unrestricted file upload in /novel-admin/src/main/java/com/java2nb/common/controller/FileController.java in novel-plus all versions allows allows an attacker to upload malicious JSP files.

  • CVE-2021-41921CriApr 28, 2022
    risk 0.64cvss 9.8epss 0.02

    novel-plus V3.6.1 allows unrestricted file uploads. Unrestricted file suffixes and contents can lead to server attacks and arbitrary code execution.

  • CVE-2024-33383HigApr 30, 2024
    risk 0.49cvss 7.5epss 0.01

    Arbitrary File Read vulnerability in novel-plus 4.3.0 and before allows a remote attacker to obtain sensitive information via a crafted GET request using the filePath parameter.

  • CVE-2022-36671HigSep 1, 2022
    risk 0.49cvss 7.5epss 0.00

    Novel-Plus v3.6.2 was discovered to contain an arbitrary file download vulnerability via the background file download API.

  • CVE-2022-28462HigMay 5, 2022
    risk 0.49cvss 7.5epss 0.01

    novel-plus 3.6.0 suffers from an Arbitrary file reading vulnerability.

  • CVE-2023-1594HigMar 23, 2023
    risk 0.48cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in novel-plus 3.6.2. Affected is the function MenuService of the file sys/menu/list. The manipulation of the argument sort leads to sql injection. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2025-4019HigApr 28, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. Affected is the function genCode of the file novel-admin/src/main/java/com/java2nb/common/controller/GeneratorController.java. The manipulation…

  • CVE-2023-41443HigSep 18, 2023
    risk 0.47cvss 7.2epss 0.01

    SQL injection vulnerability in Novel-Plus v.4.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /sys/menu/list.