Bookshelf Project maintains a JavaScript-based object-relational mapper and query builder focused on Node.js database applications, with disclosed vulnerabilities centered on its core Bookshelf product and input-handling weaknesses such as cross-site scripting in web page generation contexts. Current vulnerability counts, severity distribution, exploitation activity, and remediation status are shown in the live-stats panel alongside this summary.
The number and severity of CVEs published that impact products developed by Bookshelf Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24478MEDIUM The Bookshelf WordPress plugin through 2.0.4 does not sanitise or escape its "Paypal email address" setting before outputting it in the page, leading to an authenticated Stored Cro | Aug 2, 2021 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bookshelf Project.
Media articles that mention a CVE ID that affects a product developed by Bookshelf Project — matched by CVE ID, not by vendor name.