VYPR
Vendor

Linyuanyi1

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2026-90939MedSep 14, 2026
    risk 0.42cvss 6.5epss

    novel-plus through 5.3.3 contains an information disclosure vulnerability in the /sys/user/list endpoint that lacks proper permission annotations. Authenticated attackers can retrieve password hashes and personal data including email addresses and phone numbers for users within…

  • CVE-2026-90940MedSep 14, 2026
    risk 0.27cvss 5.3epss

    novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows anonymous attackers to invalidate portal caches by supplying the hardcoded default value in the URL path. Attackers can trigger unauthorized…

  • CVE-2026-90941MedSep 14, 2026
    risk 0.21cvss 4.3epss

    novel-plus through 5.3.3 contains an authorization bypass vulnerability in the BookController download endpoint that allows authenticated backend accounts to export complete book text including paid chapters. Attackers can supply a bookId and bookName to retrieve all chapter…