VulnSea

novel-plus vulnerabilities

CVEs whose affected-version data names the novel-plus package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

3 CVEsRSS

CVE-2026-90941Medium· 4.3PoC
1w ago

novel-plus through 5.3.3 contains an authorization bypass vulnerability in the BookController download endpoint that allows authenticated backend accounts to export complete book text including paid chapters

novel-plus through 5.3.3 contains an authorization bypass vulnerability in the BookController download endpoint that allows authenticated backend accounts to export complete book text including paid chapters. Attackers can supply a bookI…

▾ Twilight201206030 · novel-plusEPSS 0.23%via NVD
CVE-2026-90940Medium· 5.3PoC
1w ago

novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows anonymous attackers to invalidate portal caches by supplying the hardcoded default value in the URL …

novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows anonymous attackers to invalidate portal caches by supplying the hardcoded default value in the URL …

▾ Twilight201206030 · novel-plusEPSS 0.31%via NVD
CVE-2026-90939Medium· 6.5PoC
1w ago

novel-plus through 5.3.3 contains an information disclosure vulnerability in the /sys/user/list endpoint that lacks proper permission annotations

novel-plus through 5.3.3 contains an information disclosure vulnerability in the /sys/user/list endpoint that lacks proper permission annotations. Authenticated attackers can retrieve password hashes and personal data including email add…

▾ Twilight201206030 · novel-plusEPSS 0.26%via NVD
novel-plus vulnerabilities (CVEs) · VulnSea