Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

novel-plus — Vulnerabilities & Security Advisories 25

All 25 CVE vulnerabilities found in novel-plus, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities associated with the novel-plus product, categorized by specific weakness types and vendor advisory tags. It collects records of security flaws affecting this software component, covering the full historical time range from the product's release through the latest reported incidents. Here, you can track the vendor's security advisories, analyze the prevalence of a particular weakness class, and review the complete vulnerability history for the novel-plus product to understand its security posture over time.

Vendor: n/a

CVE ID Title CVSS Severity Published
CVE-2026-90941 novel-plus through 5.3.3 Missing Authorization on the Admin Book Download Endpoint CWE-862 4.3 Medium 2026-09-14
CVE-2026-90940 novel-plus through 5.3.3 Default Cache Management Password in the Front Portal CWE-1392 5.3 Medium 2026-09-14
CVE-2026-90939 novel-plus through 5.3.3 Missing Authorization on the Admin /sys/user/list Endpoint CWE-862 6.5 Medium 2026-09-14
CVE-2025-6535 xxyopen/201206030 novel-plus User Management Module UserMapper.xml list sql injection CWE-89 6.3 Medium 2025-06-24
CVE-2025-6534 xxyopen/201206030 novel-plus File FileController.java remove resource injection CWE-99 4.2 Medium 2025-06-24
CVE-2025-6533 xxyopen/201206030 novel-plus CATCHA LoginController.java ajaxLogin authentication replay CWE-294 5.6 Medium 2025-06-24
CVE-2025-4019 20120630 Novel-Plus GeneratorController.java genCode missing authentication CWE-306 7.3 High 2025-04-28
CVE-2025-4018 20120630 Novel-Plus CrawlController.java addCrawlSource missing authentication CWE-306 5.3 Medium 2025-04-28
CVE-2025-4017 20120630 Novel-Plus LogController.java list improper authorization CWE-285 4.3 Medium 2025-04-28
CVE-2025-4016 20120630 Novel-Plus LogController.java deleteIndex improper authorization CWE-285 5.4 Medium 2025-04-28
CVE-2025-4015 20120630 Novel-Plus SessionController.java list missing authentication CWE-306 5.3 Medium 2025-04-28
CVE-2025-3856 xxyopen Novel-Plus searchByPage sql injection CWE-89 6.3 Medium 2025-04-22
CVE-2025-3676 xxyopen Novel-Plus books sql injection CWE-89 6.3 Medium 2025-04-16
CVE-2025-3369 xxyopen Novel-Plus list sql injection CWE-89 6.3 Medium 2025-04-07
CVE-2024-0941 Novel-Plus list sql injection CWE-89 5.5 Medium 2024-01-26
CVE-2024-0655 Novel-Plus list sql injection CWE-89 5.5 Medium 2024-01-18
CVE-2023-7171 Novel-Plus Friendly Link FriendLinkController.java cross site scripting CWE-79 2.4 Low 2023-12-29
CVE-2023-7166 Novel-Plus HTTP POST Request updateUserInfo cross site scripting CWE-79 3.5 Low 2023-12-29
CVE-2023-2041 novel-plus sql injection CWE-89 6.3 Medium 2023-04-14
CVE-2023-2040 novel-plus sql injection CWE-89 6.3 Medium 2023-04-14
CVE-2023-2039 novel-plus sql injection CWE-89 6.3 Medium 2023-04-14
CVE-2023-1607 novel-plus list sql injection CWE-89 4.7 Medium 2023-03-23
CVE-2023-1606 novel-plus DictController.java sql injection CWE-89 6.3 Medium 2023-03-23
CVE-2023-1595 novel-plus list sql injection CWE-89 4.7 Medium 2023-03-23
CVE-2023-1594 novel-plus list MenuService sql injection CWE-89 7.3 High 2023-03-23

All 25 known CVE vulnerabilities affecting novel-plus with full Chinese analysis, references, and POCs where available.