CWE-918— Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.— MITRE CWE catalog
3,315 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-918page 1 of 67
- CVE-2002-1484CRITICALCVSS 9.8EG 9.82003-04-22
DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other systems (port scan) via a request for a URL that specifies the target IP address and port, …
- CVE-2004-2061CRITICALCVSS 9.8EG 9.82004-07-27
RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) http://, (2) ftp://, or (3) file:// URL.
- CVE-2007-6758HIGHCVSS 7.5EG 7.52020-01-23
Server-side request forgery (SSRF) vulnerability in feed-proxy.php in extjs 5.0.0.
- CVE-2010-1637MEDIUMCVSS 6.5EG 6.52010-06-22
The Mail Fetch plugin in SquirrelMail 1.4.20 and earlier allows remote authenticated users to bypass firewall restrictions and use SquirrelMail as a proxy to scan internal networks via a modified POP3 port number.
- CVE-2012-10018HIGHCVSS 8.3EG 8.32024-10-16
The Mapplic and Mapplic Lite plugins for WordPress are vulnerable to Server-Side Request Forgery in versions up to, and including 6.1, 1.0 respectively. This makes it possible for attackers to forgery requests coming from a vulnerable site…
- CVE-2013-4864CRITICALCVSS 9.8EG 9.82020-01-28
MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url parameter to cgi-bin/cmh/proxy.sh, related to a Server-Side Request Forgery (SSRF) issue.
- CVE-2014-3990CRITICALCVSS 9.8EG 9.82018-03-20
The Cart::getProducts method in system/library/cart.php in OpenCart 1.5.6.4 and earlier allows remote attackers to conduct server-side request forgery (SSRF) attacks or possibly conduct XML External Entity (XXE) attacks and execute arbitra…
- CVE-2014-8943HIGHCVSS 8.8EG 8.82020-06-01
Lexiglot through 2014-11-20 allows SSRF via the admin.php?page=projects svn_url parameter.
- CVE-2015-7570HIGHCVSS 7.2EG 7.22017-04-24
Multiple server-side request forgery (SSRF) vulnerabilities in Yeager CMS 1.2.1 allow remote attackers to trigger outbound requests and enumerate open ports via the dbhost parameter to libs/org/adodb_lite/tests/test_adodb_lite.php, libs/or…
- CVE-2015-8813HIGHCVSS 8.2EG 8.22017-03-03
The Page_Load function in Umbraco.Web/umbraco.presentation/umbraco/dashboard/FeedProxy.aspx.cs in Umbraco before 7.4.0 allows remote attackers to conduct server-side request forgery (SSRF) attacks via the url parameter.
- CVE-2016-10926CRITICALCVSS 10.0EG 10.02019-08-22
The nelio-ab-testing plugin before 4.5.9 for WordPress has SSRF in ajax/iesupport.php.
- CVE-2016-10927CRITICALCVSS 10.0EG 10.02019-08-22
The nelio-ab-testing plugin before 4.5.11 for WordPress has SSRF in ajax/iesupport.php.
- CVE-2016-3718CRITICALCVSS 5.5EG 9.0⚠ KEV2016-05-05
The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.
- CVE-2016-4029HIGHCVSS 8.6EG 8.62016-08-07
WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address.
- CVE-2016-4046MEDIUMCVSS 5.8EG 5.82016-12-15
An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. The API to configure external mail accounts can be abused to map and access network components within the trust boundary of the operator. Users can inject arbitrary h…
- CVE-2016-4374HIGHCVSS 7.7EG 7.72016-08-08
HPE Release Control (RC) 9.13, 9.20, and 9.21 before 9.21.0005 p4 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks, and consequently obtain sensitive information or cause a denial of service, via unsp…
- CVE-2016-5968MEDIUMCVSS 5.3EG 5.32016-11-25
The Replay Server in IBM Tealeaf Customer Experience 8.x before 8.7.1.8847 FP10, 8.8.x before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108 FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224 FP…
- CVE-2016-6001LOWCVSS 3.1EG 3.12017-02-01
IBM Forms Experience Builder could be susceptible to a server-side request forgery (SSRF) from the application design interface allowing for some information disclosure of internal resources.
- CVE-2016-6483HIGHCVSS 8.6EG 8.62016-09-02
The media-file upload feature in vBulletin before 3.8.7 Patch Level 6, 3.8.8 before Patch Level 2, 3.8.9 before Patch Level 1, 4.x before 4.2.2 Patch Level 6, 4.2.3 before Patch Level 2, 5.x before 5.2.0 Patch Level 3, 5.2.1 before Patch L…
- CVE-2016-6621HIGHCVSS 8.6EG 8.62017-01-31
The setup script for phpMyAdmin before 4.0.10.19, 4.4.x before 4.4.15.10, and 4.6.x before 4.6.6 allows remote attackers to conduct server-side request forgery (SSRF) attacks via unspecified vectors.
- CVE-2016-7051HIGHCVSS 8.6EG 8.62017-04-14
XmlMapper in the Jackson XML dataformat component (aka jackson-dataformat-xml) before 2.7.8 and 2.8.x before 2.8.4 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors related to a DTD.
- CVE-2016-7964HIGHCVSS 8.6EG 8.62016-10-31
The sendRequest method in HTTPClient Class in file /inc/HTTPClient.php in DokuWiki 2016-06-26a and older, when media file fetching is enabled, has no way to restrict access to private networks. This allows users to scan ports of internal n…
- CVE-2016-7999HIGHCVSS 7.4EG 7.42017-01-18
ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to conduct server side request forgery (SSRF) attacks via a URL in the var_url parameter in a valider_xml action.
- CVE-2016-9417HIGHCVSS 7.4EG 7.42017-01-31
The fetch_remote_file function in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows remote attackers to conduct server-side request forgery (SSRF) attacks via unspecified vectors.
- CVE-2016-9752HIGHCVSS 8.6EG 8.62016-12-01
In Serendipity before 2.0.5, an attacker can bypass SSRF protection by using a malformed IP address (e.g., http://127.1) or a 30x (aka Redirection) HTTP status code.
- CVE-2017-0889CRITICALCVSS 9.8EG 9.82017-11-13
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Paperclip::UriAdapter class. Attackers may be able to access information about internal network resources.
- CVE-2017-0905CRITICALCVSS 9.8EG 9.82017-11-13
The Recurly Client Ruby Library before 2.0.13, 2.1.11, 2.2.5, 2.3.10, 2.4.11, 2.5.4, 2.6.3, 2.7.8, 2.8.2, 2.9.2, 2.10.4, 2.11.3 is vulnerable to a Server-Side Request Forgery vulnerability in the "Resource#find" method that could result in…
- CVE-2017-0906CRITICALCVSS 9.8EG 9.82017-11-13
The Recurly Client Python Library before 2.0.5, 2.1.16, 2.2.22, 2.3.1, 2.4.5, 2.5.1, 2.6.2 is vulnerable to a Server-Side Request Forgery vulnerability in the "Resource.get" method that could result in compromise of API keys or other criti…
- CVE-2017-0907CRITICALCVSS 9.8EG 9.82017-11-13
The Recurly Client .NET Library before 1.0.1, 1.1.10, 1.2.8, 1.3.2, 1.4.14, 1.5.3, 1.6.2, 1.7.1, 1.8.1 is vulnerable to a Server-Side Request Forgery vulnerability due to incorrect use of "Uri.EscapeUriString" that could result in compromi…
- CVE-2017-0929HIGHCVSS 7.5EG 7.52018-07-03
DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. Attackers may be able to access information about internal network resources.
- CVE-2017-1000017HIGHCVSS 8.8EG 8.82017-07-17
phpMyAdmin 4.0, 4.4 and 4.6 are vulnerable to a weakness where a user with appropriate permissions is able to connect to an arbitrary MySQL server
- CVE-2017-1000139HIGHCVSS 8.0EG 8.02017-11-03
Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to server-side request forgery attacks as not all processes of curl redirects are checked against a white or black list. Employing …
- CVE-2017-1000237CRITICALCVSS 9.8EG 9.82017-11-17
I, Librarian version <=4.6 & 4.7 is vulnerable to Server-Side Request Forgery in the ajaxsupplement.php resulting in the attacker being able to reset any user's password.
- CVE-2017-1000419HIGHCVSS 7.5EG 7.52018-01-02
phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function resulting allowing an attacker to perform port scanning, requesting internal content and potentially attacking such internal services via the web application.
- CVE-2017-10973MEDIUMCVSS 6.5EG 6.52017-07-06
In FineCMS before 2017-07-06, application/lib/ajax/get_image_data.php has SSRF, related to requests for non-image files with a modified HTTP Host header.
- CVE-2017-11148MEDIUMCVSS 6.5EG 6.52017-08-11
Server-side request forgery (SSRF) vulnerability in link preview in Synology Chat before 1.1.0-0806 allows remote authenticated users to access intranet resources via unspecified vectors.
- CVE-2017-11149MEDIUMCVSS 6.5EG 6.52017-08-14
Server-side request forgery (SSRF) vulnerability in Downloader in Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 allows remote authenticated users to download arbitrary local files via crafted URI.
- CVE-2017-11291CRITICALCVSS 10.0EG 10.02017-12-09
An issue was discovered in Adobe Connect 9.6.2 and earlier versions. A Server-Side Request Forgery (SSRF) vulnerability exists that could be abused to bypass network access controls.
- CVE-2017-12071MEDIUMCVSS 6.5EG 6.52017-09-08
Server-side request forgery (SSRF) vulnerability in file_upload.php in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authenticated users to download arbitrary local files via the url parameter.
- CVE-2017-12905CRITICALCVSS 10.0EG 10.02017-09-25
Server Side Request Forgery vulnerability in Vebto Pixie Image Editor 1.4 and 1.7 allows remote attackers to disclose information or execute arbitrary code via the url parameter to Launderer.php.
- CVE-2017-13667CRITICALCVSS 9.9EG 9.92019-05-23
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: SSRF.
- CVE-2017-14323CRITICALCVSS 9.8EG 9.82018-04-10
SSRF (Server Side Request Forgery) in getRemoteImage.php in Ueditor in Onethink V1.0 and V1.1 allows remote attackers to obtain sensitive information, attack intranet hosts, or possibly trigger remote command execution via the upfile param…
- CVE-2017-14585HIGHCVSS 7.2EG 7.22017-11-27
A Server Side Request Forgery (SSRF) vulnerability could lead to remote code execution for authenticated administrators. This issue was introduced in version 2.2.0 of Hipchat Server and version 3.0.0 of Hipchat Data Center. Versions of Hip…
- CVE-2017-14611CRITICALCVSS 9.1EG 9.12018-04-10
SSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter, related to use of the discontinued aheinze/fetch_url_contents component.
- CVE-2017-15029MEDIUMCVSS 4.3EG 4.32019-05-23
Open-Xchange GmbH OX App Suite 7.8.4 and earlier is affected by: SSRF.
- CVE-2017-15644HIGHCVSS 8.6EG 8.62017-10-19
SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/http://INTRANET-IP:8000.
- CVE-2017-15886MEDIUMCVSS 6.5EG 6.52017-12-28
Server-side request forgery (SSRF) vulnerability in Link Preview in Synology Chat before 2.0.0-1124 allows remote authenticated users to download arbitrary local files via a crafted URI.
- CVE-2017-15943MEDIUMCVSS 5.3EG 5.32017-12-11
The configuration file import for applications, spyware and vulnerability objects functionality in the web interface in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, and 7.1.x before 7.1.14 allows remote attackers to conduc…
- CVE-2017-16614CRITICALCVSS 9.8EG 9.82018-03-30
SSRF (Server Side Request Forgery) in tpshop 2.0.5 and 2.0.6 allows remote attackers to obtain sensitive information, attack intranet hosts, or possibly trigger remote command execution via the plugins/payment/weixin/lib/WxPay.tedatac.php …
- CVE-2017-16678MEDIUMCVSS 4.7EG 4.72017-12-12
Server Side Request Forgery (SSRF) vulnerability in SAP NetWeaver Knowledge Management Configuration Service, EPBC and EPBC2 from 7.00 to 7.02; KMC-BC 7.30, 7.31, 7.40 and 7.50, that allows an attacker to manipulate the vulnerable applicat…
Map vulnerabilities like CWE-918 to your infrastructure
EchelonGraph correlates every CVE — across CWE-918 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →