Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Novel-Plus — Vulnerabilities & Security Advisories 22

All 22 CVE vulnerabilities found in Novel-Plus, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities associated with the novel-plus product, categorized under general software weakness types. It aggregates a comprehensive collection of Common Vulnerabilities and Exposures (CVEs) and other known security flaws affecting this specific software solution. The dataset covers all recorded incidents from the product's initial release through to the most recent patch updates, ensuring a complete historical view. Readers can utilize this resource to track vendor advisories and monitor the evolution of security fixes over time. It also serves as a reference for understanding specific weakness classes that frequently impact novel-plus, allowing developers and security analysts to identify patterns in code defects. Furthermore, users can look up the product's vulnerability history to assess risk exposure and verify the efficacy of previous remediation efforts. This centralized aggregation eliminates the need to search disparate sources, providing a single point of reference for compliance audits and threat modeling. By presenting vulnerability data in a structured format, the page facilitates quicker identification of critical issues that require immediate attention. The information is organized to help stakeholders evaluate the overall security posture of the software relative to industry standards. This approach supports informed decision-making regarding updates, patches, and potential migration strategies for systems relying on novel-plus. The content is strictly informational, aimed at technical audiences seeking detailed insights into the software's security landscape without unnecessary commentary.

Vendor: n/a

CVE IDTitleCVSSSeverityPublished
CVE-2025-6535 xxyopen/201206030 novel-plus User Management Module UserMapper.xml list sql injection CWE-89 6.3 Medium2025-06-24
CVE-2025-6534 xxyopen/201206030 novel-plus File FileController.java remove resource injection CWE-99 4.2 Medium2025-06-24
CVE-2025-6533 xxyopen/201206030 novel-plus CATCHA LoginController.java ajaxLogin authentication replay CWE-294 5.6 Medium2025-06-24
CVE-2025-4019 20120630 Novel-Plus GeneratorController.java genCode missing authentication CWE-306 7.3 High2025-04-28
CVE-2025-4018 20120630 Novel-Plus CrawlController.java addCrawlSource missing authentication CWE-306 5.3 Medium2025-04-28
CVE-2025-4017 20120630 Novel-Plus LogController.java list improper authorization CWE-285 4.3 Medium2025-04-28
CVE-2025-4016 20120630 Novel-Plus LogController.java deleteIndex improper authorization CWE-285 5.4 Medium2025-04-28
CVE-2025-4015 20120630 Novel-Plus SessionController.java list missing authentication CWE-306 5.3 Medium2025-04-28
CVE-2025-3856 xxyopen Novel-Plus searchByPage sql injection CWE-89 6.3 Medium2025-04-22
CVE-2025-3676 xxyopen Novel-Plus books sql injection CWE-89 6.3 Medium2025-04-16
CVE-2025-3369 xxyopen Novel-Plus list sql injection CWE-89 6.3 Medium2025-04-07
CVE-2024-0941 Novel-Plus list sql injection CWE-89 5.5 Medium2024-01-26
CVE-2024-0655 Novel-Plus list sql injection CWE-89 5.5 Medium2024-01-18
CVE-2023-7171 Novel-Plus Friendly Link FriendLinkController.java cross site scripting CWE-79 2.4 Low2023-12-29
CVE-2023-7166 Novel-Plus HTTP POST Request updateUserInfo cross site scripting CWE-79 3.5 Low2023-12-29
CVE-2023-2041 novel-plus sql injection CWE-89 6.3 Medium2023-04-14
CVE-2023-2040 novel-plus sql injection CWE-89 6.3 Medium2023-04-14
CVE-2023-2039 novel-plus sql injection CWE-89 6.3 Medium2023-04-14
CVE-2023-1607 novel-plus list sql injection CWE-89 4.7 Medium2023-03-23
CVE-2023-1606 novel-plus DictController.java sql injection CWE-89 6.3 Medium2023-03-23
CVE-2023-1595 novel-plus list sql injection CWE-89 4.7 Medium2023-03-23
CVE-2023-1594 novel-plus list MenuService sql injection CWE-89 7.3 High2023-03-23

All 22 known CVE vulnerabilities affecting Novel-Plus with full Chinese analysis, references, and POCs where available.