Browse all 3 CVE security advisories affecting Shelf-nu. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-54166 | Shelf Vulnerable to Server-Side Request Forgery (SSRF) via Asset CSV Import imageUrl Validation Bypass — shelf.nu CWE-918 | 7.1 | High | 2026-09-11 |
| CVE-2026-47697 | Shelf has cross-organization IDOR: authenticated users could read/attach another workspace's assets, tags, custodians, bookings, QR codes and audit data — shelf.nu CWE-863 | 7.1 | High | 2026-07-21 |
| CVE-2026-44204 | Shelf: SQL Injection via sortBy Parameter — shelf.nu CWE-20 | 6.5 | Medium | 2026-05-12 |
This page lists every published CVE security advisory associated with Shelf-nu. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.