Xxyopen maintains a focused but prominently represented portfolio centered on its Novel product line and cloud variants, which occupy a notable position in the vulnerability landscape despite the narrow product scope. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes, reflecting the web-application architecture and server-side processing that characterize these deployments. The recurring weakness classes—SQL injection, unrestricted file upload, cross-site scripting, injection flaws, and improper authentication—are deeply rooted in input handling, output encoding, and access control across the product stack and represent foundational web-application security challenges endemic to this vendor's codebase. Defenders should treat Xxyopen advisories as high-priority within their environment if these products are deployed, particularly where they face untrusted input or user-facing interfaces. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xxyopen over time
Signals from CVEs in this vendor scope (53 CVEs).
53 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-41921CRITICAL novel-plus V3.6.1 allows unrestricted file uploads. Unrestricted file suffixes and contents can lead to server attacks and arbitrary code execution. | Apr 28, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-36672CRITICAL Novel-Plus v3.6.2 was discovered to contain a hard-coded JWT key located in the project config file. This vulnerability allows attackers to create a custom user session. | Sep 1, 2022 | 9.8 | 31 | NO | NO |
CVE-2023-1594CRITICAL A vulnerability, which was classified as critical, was found in novel-plus 3.6.2. Affected is the function MenuService of the file sys/menu/list. The manipulation of the argument s | Mar 23, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-35121CRITICAL Novel-Plus v3.6.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /service/impl/BookServiceImpl.java. | Aug 17, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-42967CRITICAL Unrestricted file upload in /novel-admin/src/main/java/com/java2nb/common/controller/FileController.java in novel-plus all versions allows allows an attacker to upload malicious JS | May 13, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-24568CRITICAL Novel-plus v3.6.0 was discovered to be vulnerable to Server-Side Request Forgery (SSRF) via user-supplied crafted input. | Feb 10, 2022 | 9.8 | 30 | NO | NO |
CVE-2023-1606CRITICAL A vulnerability was found in novel-plus 3.6.2 and classified as critical. Affected by this issue is some unknown functionality of the file DictController.java. The manipulation of | Mar 23, 2023 | 9.8 | 29 | NO | NO |
CVE-2025-3856CRITICAL A vulnerability was found in xxyopen Novel-Plus 5.1.0. It has been classified as critical. This affects the function searchByPage of the file /book/searchByPage. The manipulation o | Apr 22, 2025 | 9.8 | 28 | NO | NO |
CVE-2024-24017CRITICAL A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /comm | Feb 8, 2024 | 9.8 | 28 | NO | NO |
CVE-2023-37847CRITICAL novel-plus v3.6.2 was discovered to contain a SQL injection vulnerability. | Aug 14, 2023 | 9.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (53 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xxyopen.
Media articles that mention a CVE ID that affects a product developed by Xxyopen — matched by CVE ID, not by vendor name.