📦 Novel Plus

by Xxyopen

🔍 What is Novel Plus?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-45890

CRITICAL CVSS 9.8 Jun 20, 2025

A directory traversal vulnerability in novel plus allows remote attackers to read, write, or execute arbitrary files on the server by manipulating the filePath parameter. This affects all novel plus i...

CVE-2024-25274

CRITICAL CVSS 9.8 Feb 20, 2024

This vulnerability allows attackers to upload arbitrary files to Novel-Plus systems via the /sysFile/upload endpoint, potentially leading to remote code execution. It affects Novel-Plus v4.3.0-RC1 ins...

CVE-2024-24014

CRITICAL CVSS 9.8 Feb 8, 2024

A SQL injection vulnerability in Novel-Plus v4.3.0-RC1 and earlier allows attackers to execute arbitrary SQL commands by manipulating offset, limit, and sort parameters in the /novel/author/list endpo...

CVE-2024-24021

CRITICAL CVSS 9.8 Feb 8, 2024

A SQL injection vulnerability in Novel-Plus v4.3.0-RC1 and earlier allows attackers to execute arbitrary SQL commands by manipulating offset, limit, and sort parameters in the /novel/userFeedback/list...

CVE-2024-24023

CRITICAL CVSS 9.8 Feb 8, 2024

A SQL injection vulnerability in Novel-Plus v4.3.0-RC1 and earlier allows attackers to inject malicious SQL commands via offset, limit, and sort parameters in the /novel/bookContent/list endpoint. Thi...

CVE-2024-24025

CRITICAL CVSS 9.8 Feb 8, 2024

An arbitrary file upload vulnerability in Novel-Plus v4.3.0-RC1 and earlier allows attackers to upload malicious files by manipulating the filename parameter in the upload() function. This can lead to...

CVE-2024-24019

CRITICAL CVSS 9.8 Feb 7, 2024

A SQL injection vulnerability in Novel-Plus v4.3.0-RC1 and earlier allows attackers to execute arbitrary SQL commands via crafted offset, limit, and sort parameters in the /system/roleDataPerm/list en...

CVE-2024-24015

CRITICAL CVSS 9.8 Feb 6, 2024

A SQL injection vulnerability in Novel-Plus v4.3.0-RC1 and earlier allows attackers to execute arbitrary SQL commands via crafted offset, limit, and sort parameters in the /sys/user/exit endpoint. Thi...

CVE-2023-46981

CRITICAL CVSS 9.8 Nov 5, 2023

A SQL injection vulnerability in Novel-Plus v4.2.0 allows remote attackers to execute arbitrary SQL commands via the sort parameter in the /common/log/list endpoint. This can lead to data theft, data ...

CVE-2023-30058

CRITICAL CVSS 9.8 Sep 11, 2023

CVE-2023-30058 is a SQL injection vulnerability in novel-plus version 3.6.2 that allows attackers to execute arbitrary SQL commands. This affects all systems running the vulnerable version of novel-pl...

CVE-2023-37847

CRITICAL CVSS 9.8 Aug 14, 2023

CVE-2023-37847 is a SQL injection vulnerability in novel-plus v3.6.2 that allows attackers to execute arbitrary SQL commands. This affects all systems running the vulnerable version of novel-plus, pot...

CVE-2021-42967

CRITICAL CVSS 9.8 May 13, 2022

This vulnerability allows attackers to upload malicious JSP files without restrictions in novel-plus's file controller. It affects all versions of novel-plus, enabling remote code execution on affecte...

CVE-2021-41921

CRITICAL CVSS 9.8 Apr 28, 2022

CVE-2021-41921 is an unrestricted file upload vulnerability in novel-plus V3.6.1 that allows attackers to upload malicious files with arbitrary extensions and content. This affects all novel-plus V3.6...

CVE-2022-24568

CRITICAL CVSS 9.8 Feb 10, 2022

CVE-2022-24568 is a Server-Side Request Forgery (SSRF) vulnerability in Novel-plus v3.6.0 that allows attackers to make arbitrary HTTP requests from the vulnerable server. This can lead to internal ne...

CVE-2025-4019

HIGH CVSS 7.3 Apr 28, 2025

A critical authentication bypass vulnerability in Novel-Plus allows remote attackers to access the code generation function without authentication. This affects Novel-Plus versions up to commit 0e156c...

CVE-2024-33383

HIGH CVSS 7.5 Apr 30, 2024

This vulnerability allows remote attackers to read arbitrary files on novel-plus servers by manipulating the filePath parameter in GET requests. It affects novel-plus versions 4.3.0 and earlier, poten...

CVE-2023-41443

HIGH CVSS 7.2 Sep 18, 2023

This SQL injection vulnerability in Novel-Plus v4.1.0 allows remote attackers to execute arbitrary SQL commands via the sort parameter in the /sys/menu/list endpoint. Attackers can potentially read, m...

CVE-2023-1594

HIGH CVSS 7.3 Mar 23, 2023

This critical SQL injection vulnerability in novel-plus 3.6.2 allows remote attackers to execute arbitrary SQL commands via the 'sort' parameter in the MenuService function. Attackers can potentially ...

CVE-2022-28462

HIGH CVSS 7.5 May 5, 2022

CVE-2022-28462 is an arbitrary file reading vulnerability in novel-plus 3.6.0 that allows attackers to read sensitive files from the server filesystem. This affects all deployments of novel-plus 3.6.0...

CVE-2025-60298

MEDIUM CVSS 5.4 Oct 8, 2025

Novel-Plus up to version 5.2.4 contains a stored XSS vulnerability in the /author/updateIndexName endpoint. Authenticated attackers can inject malicious JavaScript through the indexName parameter, whi...

CVE-2025-60299

MEDIUM CVSS 5.4 Oct 8, 2025

An authenticated user in Novel-Plus 5.2.0 can inject malicious JavaScript via the replyContent parameter when replying to book comments, leading to stored XSS. This allows execution of arbitrary code ...

CVE-2025-6534

MEDIUM CVSS 4.2 Jun 24, 2025

This vulnerability in novel-plus allows remote attackers to delete arbitrary files due to missing authorization checks in the file removal function. It affects all systems running novel-plus up to ver...

CVE-2025-6533

MEDIUM CVSS 5.6 Jun 24, 2025

This vulnerability allows attackers to bypass authentication in novel-plus by replaying CAPTCHA tokens, potentially gaining unauthorized access to administrative functions. It affects novel-plus versi...

CVE-2025-4017

MEDIUM CVSS 4.3 Apr 28, 2025

This vulnerability in Novel-Plus allows unauthorized access to log viewing functionality due to improper authorization in the LogController. Attackers can remotely view system logs without proper perm...

CVE-2025-4015

MEDIUM CVSS 5.3 Apr 28, 2025

This CVE describes an authentication bypass vulnerability in Novel-Plus software that allows unauthenticated attackers to access session management functions remotely. The vulnerability affects Novel-...

CVE-2025-3856

MEDIUM CVSS 6.3 Apr 22, 2025

This is a critical SQL injection vulnerability in xxyopen Novel-Plus 5.1.0 that allows remote attackers to execute arbitrary SQL commands via the 'sort' parameter in the /book/searchByPage endpoint. A...

CVE-2025-3676

MEDIUM CVSS 6.3 Apr 16, 2025

This critical SQL injection vulnerability in xxyopen Novel-Plus allows attackers to manipulate database queries through the /api/front/search/books endpoint. Remote attackers can potentially read, mod...

CVE-2025-26182

MEDIUM CVSS 6.5 Mar 4, 2025

This vulnerability allows remote attackers to execute arbitrary code on systems running xxyopen novel plus version 4.4.0 and earlier. The flaw exists in the PageController.java file, enabling code inj...

CVE-2023-1606

MEDIUM CVSS 6.3 Mar 23, 2023

This is a SQL injection vulnerability in novel-plus 3.6.2 that allows remote attackers to execute arbitrary SQL commands via the 'orderby' parameter in DictController.java. Attackers can potentially r...

CVE-2023-1595

MEDIUM CVSS 4.7 Mar 23, 2023

This CVE describes a SQL injection vulnerability in novel-plus version 3.6.2 that allows remote attackers to execute arbitrary SQL commands via the 'sort' parameter in the common/log/list functionalit...