CVE-2025-57964

WordPress Library Bookshelves Plugin <= 5.11 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in photonicgnostic Library Bookshelves allows Stored XSS. This issue affects Library Bookshelves: from n/a through 5.11.


We have discovered 263 live websites that are affected by CVE-2025-57964.

Run a Free Instant Scan




Affected Software

Product  Library Bookshelves
Category Wordpress Plugins
Vulnerable Domains263 live websites (100% of Library Bookshelves install base)
Vulnerable Versions
  • from 0 through 5.11
Vulnerable Versions Count6 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Sep 22, 2025
  • Updated - Sep 23, 2025

Credits

  • Muhammad Yudha - DJ (Patchstack Alliance) (finder)

Website Distribution by Country

Number of websites using CVE-2025-57964
United States210 websites



Canada10 websites
GB6 websites
France5 websites
Austria4 websites
Singapore4 websites
Germany3 websites
Netherlands2 websites
Poland2 websites

Website Distribution by TLD

Number of websites using CVE-2025-57964
.org182 websites
.com30 websites
.ca6 websites
.at4 websites
.info4 websites
.fr3 websites
.nl2 websites
.net2 websites
.eu2 websites
.it2 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-57964

Top websites that are affected by CVE-2025-57964. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*************.****.gov United States***,***
***********.info United States***,***
***.cc United States***,***
*******.*******.***.ng Nigeria***,***
*******.***.***.mz Mozambique***,***
*********.org United States*,***,***
******************.org United States*,***,***
****.org United States*,***,***
****.********.ca Canada*,***,***
**************.org United States*,***,***
See full domain list

FAQ

CVE-2025-57964 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Library Bookshelves
A total of 263 websites have been identified as vulnerable to CVE-2025-57964, based on global website indexing conducted by WebTechSurvey.
The Library Bookshelves is affected by the CVE-2025-57964 vulnerability.
Library Bookshelves versions up to and including 5.11 are vulnerable to CVE-2025-57964.