Shelf-nu

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 3
    Known Exploited: 0
    0
    Critical Level Threats
    2
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-54166

    Shelf Vulnerable to Server-Side Request Forgery (SSRF) via Asset CSV Import imageUrl Validation Bypass

    Last Modified: Sep 12, 2026
    Published: Sep 11, 2026

    CVE-2026-47697

    Shelf has cross-organization IDOR: authenticated users could read/attach another workspace's assets, tags, custodians, bookings, QR codes and audit data

    Last Modified: Jul 23, 2026
    Published: Jul 21, 2026

    CVE-2026-44204

    Shelf: SQL Injection via sortBy Parameter

    Last Modified: May 14, 2026
    Published: May 12, 2026
    Items Per Page
    Shelf-Nu Vulnerabilities & Security CVEs | CVE-DB