xxyopen CVE Vulnerabilities & Metrics

Focus on xxyopen vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About xxyopen Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with xxyopen. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total xxyopen CVEs: 32
Earliest CVE date: 10 Feb 2022, 19:15 UTC
Latest CVE date: 08 Feb 2024, 02:15 UTC

Latest CVE reference: CVE-2024-24021

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical xxyopen CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 2.82

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 18
4.0-6.9 10
7.0-8.9 4
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS xxyopen CVEs

These are the five CVEs with the highest CVSS scores for xxyopen, sorted by severity first and recency.

All CVEs for xxyopen

CVE-2024-24021 xxyopen vulnerability CVSS: 0 08 Feb 2024, 02:15 UTC

A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, limit, and sort parameters to perform SQL injection via /novel/userFeedback/list.

CVE-2024-24017 xxyopen vulnerability CVSS: 0 08 Feb 2024, 02:15 UTC

A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /common/dict/list

CVE-2024-24014 xxyopen vulnerability CVSS: 0 08 Feb 2024, 02:15 UTC

A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /novel/author/list

CVE-2024-24026 xxyopen vulnerability CVSS: 0 08 Feb 2024, 01:15 UTC

An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions at com.java2nb.system.controller.SysUserController: uploadImg(). An attacker can pass in specially crafted filename parameter to perform arbitrary File download.

CVE-2024-24025 xxyopen vulnerability CVSS: 0 08 Feb 2024, 01:15 UTC

An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileController: upload(). An attacker can pass in specially crafted filename parameter to perform arbitrary File download.

CVE-2024-24024 xxyopen vulnerability CVSS: 0 08 Feb 2024, 01:15 UTC

An arbitrary File download vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileController: fileDownload(). An attacker can pass in specially crafted filePath and fieName parameters to perform arbitrary File download.

CVE-2024-24023 xxyopen vulnerability CVSS: 0 08 Feb 2024, 01:15 UTC

A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, limit, and sort parameters to perform SQL injection via /novel/bookContent/list.

CVE-2024-24018 xxyopen vulnerability CVSS: 0 08 Feb 2024, 01:15 UTC

A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL injection via /system/dataPerm/list

CVE-2024-24019 xxyopen vulnerability CVSS: 0 07 Feb 2024, 01:15 UTC

A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL injection via /system/roleDataPerm/list

CVE-2024-24015 xxyopen vulnerability CVSS: 0 06 Feb 2024, 16:15 UTC

A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL via /sys/user/exit

CVE-2024-24013 xxyopen vulnerability CVSS: 0 06 Feb 2024, 16:15 UTC

A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /novel/pay/list

CVE-2024-0941 xxyopen vulnerability CVSS: 5.2 26 Jan 2024, 19:15 UTC

A vulnerability was found in Novel-Plus 4.3.0-RC1 and classified as critical. This issue affects some unknown processing of the file /novel/bookComment/list. The manipulation of the argument sort leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-252185 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-0655 xxyopen vulnerability CVSS: 5.2 18 Jan 2024, 03:15 UTC

A vulnerability has been found in Novel-Plus 4.3.0-RC1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /novel/bookSetting/list. The manipulation of the argument sort leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-251383.

CVE-2023-7171 xxyopen vulnerability CVSS: 3.3 29 Dec 2023, 18:15 UTC

A vulnerability was found in Novel-Plus up to 4.2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file novel-admin/src/main/java/com/java2nb/novel/controller/FriendLinkController.java of the component Friendly Link Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The patch is named d6093d8182362422370d7eaf6c53afde9ee45215. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-249307.

CVE-2023-7166 xxyopen vulnerability CVSS: 4.0 29 Dec 2023, 09:15 UTC

A vulnerability classified as problematic has been found in Novel-Plus up to 4.2.0. This affects an unknown part of the file /user/updateUserInfo of the component HTTP POST Request Handler. The manipulation of the argument nickName leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is c62da9bb3a9b3603014d0edb436146512631100d. It is recommended to apply a patch to fix this issue. The identifier VDB-249201 was assigned to this vulnerability.

CVE-2023-46981 xxyopen vulnerability CVSS: 0 05 Nov 2023, 00:15 UTC

SQL injection vulnerability in Novel-Plus v.4.2.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /common/log/list.

CVE-2023-41443 xxyopen vulnerability CVSS: 0 18 Sep 2023, 22:15 UTC

SQL injection vulnerability in Novel-Plus v.4.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /sys/menu/list.

CVE-2023-30058 xxyopen vulnerability CVSS: 0 11 Sep 2023, 16:15 UTC

novel-plus 3.6.2 is vulnerable to SQL Injection.

CVE-2023-2041 xxyopen vulnerability CVSS: 6.5 14 Apr 2023, 09:15 UTC

A vulnerability classified as critical was found in novel-plus 3.6.2. Affected by this vulnerability is an unknown functionality of the file /category/list?limit=10&offset=0&order=desc. The manipulation of the argument sort leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-225919. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-2040 xxyopen vulnerability CVSS: 6.5 14 Apr 2023, 09:15 UTC

A vulnerability classified as critical has been found in novel-plus 3.6.2. Affected is an unknown function of the file /news/list?limit=10&offset=0&order=desc. The manipulation of the argument sort leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-225918 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-2039 xxyopen vulnerability CVSS: 6.5 14 Apr 2023, 08:15 UTC

A vulnerability was found in novel-plus 3.6.2. It has been rated as critical. This issue affects some unknown processing of the file /author/list?limit=10&offset=0&order=desc. The manipulation of the argument sort leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-225917 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-1607 xxyopen vulnerability CVSS: 5.8 23 Mar 2023, 20:15 UTC

A vulnerability was found in novel-plus 3.6.2. It has been classified as critical. This affects an unknown part of the file /common/sysFile/list. The manipulation of the argument sort leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-223737 was assigned to this vulnerability.

CVE-2023-1606 xxyopen vulnerability CVSS: 6.5 23 Mar 2023, 19:15 UTC

A vulnerability was found in novel-plus 3.6.2 and classified as critical. Affected by this issue is some unknown functionality of the file DictController.java. The manipulation of the argument orderby leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-223736.

CVE-2023-1595 xxyopen vulnerability CVSS: 5.8 23 Mar 2023, 11:15 UTC

A vulnerability has been found in novel-plus 3.6.2 and classified as critical. Affected by this vulnerability is an unknown functionality of the file common/log/list. The manipulation of the argument sort leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223663.

CVE-2023-1594 xxyopen vulnerability CVSS: 7.5 23 Mar 2023, 10:15 UTC

A vulnerability, which was classified as critical, was found in novel-plus 3.6.2. Affected is the function MenuService of the file sys/menu/list. The manipulation of the argument sort leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-223662 is the identifier assigned to this vulnerability.

CVE-2022-36672 xxyopen vulnerability CVSS: 0 01 Sep 2022, 03:15 UTC

Novel-Plus v3.6.2 was discovered to contain a hard-coded JWT key located in the project config file. This vulnerability allows attackers to create a custom user session.

CVE-2022-36671 xxyopen vulnerability CVSS: 0 01 Sep 2022, 03:15 UTC

Novel-Plus v3.6.2 was discovered to contain an arbitrary file download vulnerability via the background file download API.

CVE-2022-35121 xxyopen vulnerability CVSS: 0 17 Aug 2022, 20:15 UTC

Novel-Plus v3.6.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /service/impl/BookServiceImpl.java.

CVE-2021-42967 xxyopen vulnerability CVSS: 7.5 13 May 2022, 12:15 UTC

Unrestricted file upload in /novel-admin/src/main/java/com/java2nb/common/controller/FileController.java in novel-plus all versions allows allows an attacker to upload malicious JSP files.

CVE-2022-28462 xxyopen vulnerability CVSS: 5.0 05 May 2022, 13:15 UTC

novel-plus 3.6.0 suffers from an Arbitrary file reading vulnerability.

CVE-2021-41921 xxyopen vulnerability CVSS: 7.5 28 Apr 2022, 13:15 UTC

novel-plus V3.6.1 allows unrestricted file uploads. Unrestricted file suffixes and contents can lead to server attacks and arbitrary code execution.

CVE-2022-24568 xxyopen vulnerability CVSS: 7.5 10 Feb 2022, 19:15 UTC

Novel-plus v3.6.0 was discovered to be vulnerable to Server-Side Request Forgery (SSRF) via user-supplied crafted input.