201206030 novel-plus

3 known vulnerabilities in 201206030 novel-plus, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-90941 CVSS 5.3 medium novel-plus through 5.3.3 contains an authorization bypass vulnerability in the BookController download endpoint that allows authenticated…
  • CVE-2026-90940 CVSS 6.9 medium novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows…
  • CVE-2026-90939 CVSS 7.1 high novel-plus through 5.3.3 contains an information disclosure vulnerability in the /sys/user/list endpoint that lacks proper permission…