Xxyopen
Xxyopen Novel-plus: vulnerabilidades y CVE
Xxyopen Novel-plus tiene 53 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 25 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE53
Últimos 12 meses5
Críticas25
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-90941 | Media (5.3) | 0.41% | — | 14 sept 2026 | novel-plus through 5.3.3 contains an authorization bypass vulnerability in the BookController download endpoint that allows authenticated backend accounts to export complete book text including paid chapters. Attackers… |
| CVE-2026-90940 | Media (6.9) | 0.55% | — | 14 sept 2026 | novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows anonymous attackers to invalidate portal caches by supplying the hardcoded default… |
| CVE-2026-90939 | Alta (7.1) | 0.46% | — | 14 sept 2026 | novel-plus through 5.3.3 contains an information disclosure vulnerability in the /sys/user/list endpoint that lacks proper permission annotations. Authenticated attackers can retrieve password hashes and personal data… |
| CVE-2025-60299 | Media (5.4) | 0.21% | — | 8 oct 2025 | Novel-Plus with 5.2.0 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the /book/addCommentReply endpoint. An authenticated user can inject malicious JavaScript through the replyContent… |
| CVE-2025-60298 | Media (5.4) | 0.26% | — | 8 oct 2025 | Novel-Plus up to 5.2.4 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the /author/updateIndexName endpoint. This vulnerability allows authenticated attackers to inject malicious… |
| CVE-2025-6535 | Baja (2.1) | 0.47% | — | 24 jun 2025 | A vulnerability has been found in xxyopen/201206030 novel-plus up to 5.1.3 and classified as critical. This vulnerability affects the function list of the file… |
| CVE-2025-6534 | Baja (1.3) | 0.48% | — | 24 jun 2025 | A vulnerability, which was classified as problematic, was found in xxyopen/201206030 novel-plus up to 5.1.3. This affects the function remove of the file… |
| CVE-2025-6533 | Baja (2.9) | 0.56% | — | 24 jun 2025 | A vulnerability, which was classified as critical, has been found in xxyopen/201206030 novel-plus up to 5.1.3. Affected by this issue is the function ajaxLogin of the file… |
| CVE-2025-45890 | Crítica (9.8) | 1.6% | — | 20 jun 2025 | Directory Traversal vulnerability in novel plus before v.5.1.0 allows a remote attacker to execute arbitrary code via the filePath parameter |
| CVE-2025-4019 | Media (6.9) | 0.70% | — | 28 abr 2025 | A vulnerability, which was classified as critical, was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. Affected is the function genCode of the file… |
| CVE-2025-4018 | Media (6.9) | 0.83% | — | 28 abr 2025 | A vulnerability, which was classified as critical, has been found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This issue affects the function addCrawlSource of the file… |
| CVE-2025-4017 | Media (5.3) | 0.55% | — | 28 abr 2025 | A vulnerability classified as problematic was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This vulnerability affects the function list of the file… |
| CVE-2025-4016 | Media (5.3) | 0.50% | — | 28 abr 2025 | A vulnerability classified as critical has been found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This affects the function deleteIndex of the file… |
| CVE-2025-4015 | Media (6.9) | 0.83% | — | 28 abr 2025 | A vulnerability was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. It has been rated as critical. Affected by this issue is the function list of the file… |
| CVE-2025-3856 | Media (5.3) | 0.59% | — | 22 abr 2025 | A vulnerability was found in xxyopen Novel-Plus 5.1.0. It has been classified as critical. This affects the function searchByPage of the file /book/searchByPage. The manipulation of the argument sort leads to sql… |
| CVE-2025-3676 | Media (5.3) | 0.55% | — | 16 abr 2025 | A vulnerability classified as critical has been found in xxyopen Novel-Plus 3.5.0. This affects an unknown part of the file /api/front/search/books. The manipulation of the argument sort leads to sql injection. It is… |
| CVE-2025-3369 | Media (5.3) | 0.56% | — | 7 abr 2025 | A vulnerability was found in xxyopen Novel-Plus 5.1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /novel/friendLink/list. The manipulation of the argument sort leads… |
| CVE-2025-26182 | Media (6.5) | 0.49% | — | 4 mar 2025 | An issue in xxyopen novel plus v.4.4.0 and before allows a remote attacker to execute arbitrary code via the PageController.java file |
| CVE-2024-33383 | Alta (7.5) | 0.67% | — | 30 abr 2024 | Arbitrary File Read vulnerability in novel-plus 4.3.0 and before allows a remote attacker to obtain sensitive information via a crafted GET request using the filePath parameter. |
| CVE-2024-25274 | Crítica (9.8) | 0.78% | — | 20 feb 2024 | An arbitrary file upload vulnerability in the component /sysFile/upload of Novel-Plus v4.3.0-RC1 allows attackers to execute arbitrary code via uploading a crafted file. |
| CVE-2024-24021 | Crítica (9.8) | 0.62% | — | 8 feb 2024 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, limit, and sort parameters to perform SQL injection via /novel/userFeedback/list. |
| CVE-2024-24017 | Crítica (9.8) | 0.63% | — | 8 feb 2024 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /common/dict/list |
| CVE-2024-24014 | Crítica (9.8) | 0.62% | — | 8 feb 2024 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /novel/author/list |
| CVE-2024-24026 | Crítica (9.8) | 0.69% | — | 8 feb 2024 | An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions at com.java2nb.system.controller.SysUserController: uploadImg(). An attacker can pass in specially crafted filename parameter to… |
| CVE-2024-24025 | Crítica (9.8) | 0.65% | — | 8 feb 2024 | An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileController: upload(). An attacker can pass in specially crafted filename parameter to perform… |
| CVE-2024-24024 | Crítica (9.8) | 0.65% | — | 8 feb 2024 | An arbitrary File download vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileController: fileDownload(). An attacker can pass in specially crafted filePath and fieName… |
| CVE-2024-24023 | Crítica (9.8) | 0.62% | — | 8 feb 2024 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, limit, and sort parameters to perform SQL injection via /novel/bookContent/list. |
| CVE-2024-24018 | Crítica (9.8) | 0.61% | — | 8 feb 2024 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL injection via /system/dataPerm/list |
| CVE-2024-24019 | Crítica (9.8) | 0.59% | — | 7 feb 2024 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL injection via /system/roleDataPerm/list |
| CVE-2024-24015 | Crítica (9.8) | 0.61% | — | 6 feb 2024 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL via /sys/user/exit |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.