CVE-2025-45890: Xxyopen Novel-Plus

Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.

Directory Traversal vulnerability in novel plus before v.5.1.0 allows a remote attacker to execute arbitrary code via the filePath parameter

Affected products

  • Xxyopen Novel-Plus: before 5.1.0 (fixed in 5.1.0)

Published 2025-06-20. Last modified 2026-06-17.