VYPR

novel-plus

by Novel Plus

Source repositories

CVEs (45)

  • CVE-2025-4017MedApr 28, 2025
    risk 0.28cvss 4.3epss 0.01

    A vulnerability classified as problematic was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This vulnerability affects the function list of the file nnovel-admin/src/main/java/com/java2nb/common/controller/LogController.java. The manipulation leads…

  • CVE-2026-90940MedSep 14, 2026
    risk 0.27cvss 5.3epss 0.00

    novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows anonymous attackers to invalidate portal caches by supplying the hardcoded default value in the URL path. Attackers can trigger unauthorized…

  • CVE-2026-90941MedSep 14, 2026
    risk 0.21cvss 4.3epss 0.00

    novel-plus through 5.3.3 contains an authorization bypass vulnerability in the BookController download endpoint that allows authenticated backend accounts to export complete book text including paid chapters. Attackers can supply a bookId and bookName to retrieve all chapter…

  • CVE-2023-7171LowDec 29, 2023
    risk 0.00cvss 2.4epss 0.01

    A vulnerability was found in Novel-Plus up to 4.2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file novel-admin/src/main/java/com/java2nb/novel/controller/FriendLinkController.java of the component Friendly Link…

  • CVE-2023-7166LowDec 29, 2023
    risk 0.00cvss 3.5epss 0.01

    A vulnerability classified as problematic has been found in Novel-Plus up to 4.2.0. This affects an unknown part of the file /user/updateUserInfo of the component HTTP POST Request Handler. The manipulation of the argument nickName leads to cross site scripting. It is possible…

Page 3 of 3