Vulnerabilities > Xxyopen

DATE CVE VULNERABILITY TITLE RISK
2022-08-17 CVE-2022-35121 SQL Injection vulnerability in Xxyopen Novel-Plus 3.6.1
Novel-Plus v3.6.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /service/impl/BookServiceImpl.java.
network
low complexity
xxyopen CWE-89
critical
9.8
2022-05-13 CVE-2021-42967 Unrestricted Upload of File with Dangerous Type vulnerability in Xxyopen Novel-Plus
Unrestricted file upload in /novel-admin/src/main/java/com/java2nb/common/controller/FileController.java in novel-plus all versions allows allows an attacker to upload malicious JSP files.
network
low complexity
xxyopen CWE-434
critical
9.8
2022-05-05 CVE-2022-28462 Files or Directories Accessible to External Parties vulnerability in Xxyopen Novel-Plus 3.6.0
novel-plus 3.6.0 suffers from an Arbitrary file reading vulnerability.
network
low complexity
xxyopen CWE-552
7.5
2022-04-28 CVE-2021-41921 Unrestricted Upload of File with Dangerous Type vulnerability in Xxyopen Novel-Plus 3.6.1
novel-plus V3.6.1 allows unrestricted file uploads.
network
low complexity
xxyopen CWE-434
critical
9.8
2022-02-10 CVE-2022-24568 Server-Side Request Forgery (SSRF) vulnerability in Xxyopen Novel-Plus 3.6.0
Novel-plus v3.6.0 was discovered to be vulnerable to Server-Side Request Forgery (SSRF) via user-supplied crafted input.
network
low complexity
xxyopen CWE-918
critical
9.8