Products: 3
    Vulnerabilities: 53
    Known Exploited: 0
    21
    Critical Level Threats
    6
    High Level Threats
    24
    Medium Level Threats
    2
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-65442

    DOM-based Cross-Site Scripting (XSS) vulnerability in 201206030 novel V3.5.0 allows remote attackers to execute arbitrary JavaScript code or disclose sensitive information (e.g., user session cookies) via a crafted "wvstest" parameter in the URL or malicious script injection into window.localStorage. The vulnerability arises from insufficient validation and encoding of user-controllable data in the book comment module: unfiltered user input is stored in the backend database (book_comment table, commentContent field) and returned via API, then rendered directly into the page DOM via Vue 3's v-html directive without sanitization. Even if modern browsers' built-in XSS filters block pop-up alerts, attackers can use concealed payloads to bypass interception and achieve actual harm.

    Last Modified: Dec 31, 2025
    Published: Dec 29, 2025

    CVE-2025-60298

    Novel-Plus up to 5.2.4 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the /author/updateIndexName endpoint. This vulnerability allows authenticated attackers to inject malicious JavaScript code through the indexName parameter, which gets stored in the database and executed when other users view the affected book chapter.

    Last Modified: Oct 10, 2025
    Published: Oct 08, 2025

    CVE-2025-60299

    Novel-Plus with 5.2.0 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the /book/addCommentReply endpoint. An authenticated user can inject malicious JavaScript through the replyContent parameter when replying to a book comment. The payload is stored in the database and is executed in other users’ browsers when they view the affected comment thread.

    Last Modified: Oct 10, 2025
    Published: Oct 08, 2025

    CVE-2025-6535

    xxyopen/201206030 novel-plus User Management Module UserMapper.xml list sql injection

    Last Modified: Jul 09, 2025
    Published: Jun 24, 2025

    CVE-2025-6534

    xxyopen/201206030 novel-plus File FileController.java remove resource injection

    Last Modified: Jul 09, 2025
    Published: Jun 24, 2025
    Items Per Page
    Xxyopen Vulnerabilities & Security CVEs | CVE-DB