diff --git a/http/cves/2025/CVE-2025-26182.yaml b/http/cves/2025/CVE-2025-26182.yaml index 37efd089ad3..89aea46ae90 100644 --- a/http/cves/2025/CVE-2025-26182.yaml +++ b/http/cves/2025/CVE-2025-26182.yaml @@ -1,9 +1,9 @@ id: CVE-2025-26182 info: - name: xxyopen novel-plus - Server-Side Template Injection + name: Xxyopen Novel-Plus v4.4.0 - Server-Side Template Injection author: pdteam - severity: critical + severity: high description: | xxyopen novel-plus v.4.4.0 and earlier contains a remote code execution vulnerability caused by Server-Side Template Injection in PageController.java. The vulnerability allows remote attackers to execute arbitrary code through unvalidated path parameters that are directly inserted into Thymeleaf template rendering. impact: | @@ -25,7 +25,7 @@ info: verified: true max-request: 1 shodan-query: title:"novel-plus" - tags: cve,cve2025,ssti,rce,novel-plus,thymeleaf + tags: cve,cve2025,ssti,rce,novel-plus,thymeleaf,xxyopen http: - method: GET