Shelf-nu
- Total products in the ecosystem
- 1
- Total vulnerabilities (90 days)
- 2
en
Verify to analyze this security profile
As of 09/29/2026, Shelf-nu recorded 2 security vulnerabilities in the last 90 days across 1 products, including 2 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, shelf.nu had the most security vulnerabilities in the Shelf-nu ecosystem, with 2 vulnerabilities—approximately 100% of the provider's total vulnerabilities during this period.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-54166Shelf Vulnerable to Server-Side Request Forgery (SSRF) via Asset CSV Import imageUrl Validation Bypass | Exploitation statusNot known exploited | FixNot confirmed | Affected productshelf.nu | Published09/11/2026 | SeverityHigh |
CVE-2026-47697Shelf has cross-organization IDOR: authenticated users could read/attach another workspace's assets, tags, custodians, bookings, QR codes and audit data | Exploitation statusNot known exploited | FixNot confirmed | Affected productshelf.nu | Published07/21/2026 | SeverityHigh |
CVE-2026-44204Shelf: SQL Injection via sortBy Parameter | Exploitation statusPublic exploit | FixYes | Affected productshelf.nu | Published05/12/2026 | SeverityMedium |