
CVE-2026-44204 Shelf is a platform for tracking physical assets. From 1.12 to before 1.20.1, a SQL injection vulnerability in the sortBy query parameter on the /assets route allows … https://www.cve.org/CVERecord?id=CVE-2026-44204
Post summary
The post reports a SQL injection flaw in Shelf’s /assets route affecting versions 1.12 to 1.20.1, with no PoC, exploit code, or patch details provided.
