CWE-918— Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.— MITRE CWE catalog
3,834 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-918page 4 of 77
- CVE-2025-64163CRITICALCVSS 9.8EG 9.82025-11-06
DataEase is an open source data visualization analysis tool. In versions 2.10.14 and below, the vendor added a blacklist to filter ldap:// and ldaps://. However, omission of protection for the dns:// protocol results in an SSRF vulnerabili…
- CVE-2025-31993CRITICALCVSS 9.8EG 9.82025-10-12
HCL Unica Centralized Offer Management is vulnerable to a potential Server-Side Request Forgery (SSRF). An attacker can exploit improper input validation by submitting maliciously crafted input to a target application running on a server.
- CVE-2025-11046CRITICALCVSS 9.8EG 9.82025-09-26
A security flaw has been discovered in Tencent WeKnora 0.1.0. This impacts the function testEmbeddingModel of the file /api/v1/initialization/embedding/test. The manipulation of the argument baseUrl results in server-side request forgery. …
- CVE-2025-58045CRITICALCVSS 9.8EG 9.82025-09-15
Dataease is an open source data analytics and visualization platform. In Dataease versions up to 2.10.12, the patch introduced to mitigate DB2 JDBC deserialization remote code execution attacks only blacklisted the rmi parameter. The ldap …
- CVE-2024-9408CRITICALCVSS 9.8EG 9.82025-07-16
In Eclipse GlassFish since version 6.2.5 it is possible to perform a Server Side Request Forgery attack in specific endpoints.
- CVE-2025-45872CRITICALCVSS 9.8EG 9.82025-07-01
zrlog v3.1.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the downloadUrl parameter.
- CVE-2025-6517CRITICALCVSS 9.8EG 9.82025-06-23
A vulnerability was found in Dromara MaxKey up to 4.1.7 and classified as critical. This issue affects the function Add of the file maxkey-webs\maxkey-web-mgt\src\main\java\org\dromara\maxkey\web\apps\contorller\SAML20DetailsController.jav…
- CVE-2025-5510CRITICALCVSS 9.8EG 9.82025-06-03
A vulnerability classified as critical was found in quequnlong shiyi-blog up to 1.2.1. This vulnerability affects unknown code of the file /app/sys/article/optimize. The manipulation of the argument url leads to server-side request forgery…
- CVE-2025-37090CRITICALCVSS 9.8EG 9.82025-06-02
A server-side request forgery vulnerability exists in HPE StoreOnce Software.
- CVE-2024-48590CRITICALCVSS 9.8EG 9.82025-03-20
Inflectra SpiraTeam 7.2.00 is vulnerable to Server-Side Request Forgery (SSRF) via the NewsReaderService. This allows an attacker to escalate privileges and obtain sensitive information.
- CVE-2024-12450CRITICALCVSS 9.8EG 9.82025-03-20
In infiniflow/ragflow versions 0.12.0, the `web_crawl` function in `document_app.py` contains multiple vulnerabilities. The function does not filter URL parameters, allowing attackers to exploit Full Read SSRF by accessing internal network…
- CVE-2025-27655CRITICALCVSS 9.8EG 9.82025-03-05
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Server-Side Request Forgery: CPA v1 V-2023-009.
- CVE-2025-27652CRITICALCVSS 9.8EG 9.82025-03-05
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Server-Side Request Forgery: rfIDEAS V-2023-015.
- CVE-2025-27651CRITICALCVSS 9.8EG 9.82025-03-05
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Server-Side Request Forgery: Elatec V-2023-014.
- CVE-2025-22952CRITICALCVSS 9.8EG 9.82025-02-27
elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perform SSRF attacks.
- CVE-2024-55875CRITICALCVSS 9.8EG 9.82024-12-12
http4k is a functional toolkit for Kotlin HTTP applications. Prior to version 6.50.0.0, there is a potential XXE (XML External Entity Injection) vulnerability when http4k handling malicious XML contents within requests, which might allow a…
- CVE-2024-48874CRITICALCVSS 9.8EG 9.82024-12-06
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could give attackers the ability to force Ruijie's proxy servers to perform any request the attackers choose. Using this, attackers could access internal services used by Rui…
- CVE-2024-47208CRITICALCVSS 9.8EG 9.82024-11-18
Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.17. Users are recommended to upgrade to version 18.12.17, which fi…
- CVE-2024-51358CRITICALCVSS 9.8EG 9.82024-11-05
An issue in Linux Server Heimdall v.2.6.1 allows a remote attacker to execute arbitrary code via a crafted script to the Add new application.
- CVE-2024-47167CRITICALCVSS 9.8EG 9.82024-10-10
Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to **Server-Side Request Forgery (SSRF)** in the `/queue/join` endpoint. Gradio’s `async_save_url_to_cache` function allows attackers to f…
- CVE-2024-47222CRITICALCVSS 9.8EG 9.82024-09-23
New Cloud MyOffice SDK Collaborative Editing Server 2.2.2 through 2.8 allows SSRF via manipulation of requests from external document storage via the MS-WOPI protocol.
- CVE-2024-38183CRITICALCVSS 9.8EG 9.82024-09-17
An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network.
- CVE-2024-44677CRITICALCVSS 9.8EG 9.82024-09-10
eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the DatabaseController.java component.
- CVE-2024-44721CRITICALCVSS 9.8EG 9.82024-09-09
SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /admin_reslib.php.
- CVE-2024-45507CRITICALCVSS 9.8EG 9.82024-09-04
Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fi…
- CVE-2024-41570CRITICALCVSS 9.8EG 9.82024-08-12
An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send arbitrary network traffic originating from the team server.
- CVE-2024-6980CRITICALCVSS 9.8EG 9.82024-07-31
A verbose error handling issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request forgery. This issue only affects GravityZone Console versions before 6.38.1-5 running only…
- CVE-2024-41120CRITICALCVSS 9.8EG 9.82024-07-26
streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `url` variable on line 63 of `pages/9_🔲_Vector_Data_Visualization.py` takes user input, which i…
- CVE-2024-29319CRITICALCVSS 9.8EG 9.82024-07-05
Volmarg Personal Management System 1.4.64 is vulnerable to SSRF (Server Side Request Forgery) via uploading a SVG file. The server can make unintended HTTP and DNS requests to a server that the attacker controls.
- CVE-2024-5822CRITICALCVSS 9.8EG 9.82024-06-27
A Server-Side Request Forgery (SSRF) vulnerability exists in the upload processing interface of gaizhenbiao/ChuanhuChatGPT versions <= ChuanhuChatGPT-20240410-git.zip. This vulnerability allows attackers to send crafted requests from the v…
- CVE-2024-5482CRITICALCVSS 9.8EG 9.82024-06-06
A Server-Side Request Forgery (SSRF) vulnerability exists in the 'add_webpage' endpoint of the parisneo/lollms-webui application, affecting the latest version. The vulnerability arises because the application does not adequately validate U…
- CVE-2023-46295CRITICALCVSS 9.8EG 9.82024-05-01
An issue was discovered in Teledyne FLIR M300 2.00-19. Unauthenticated remote code execution can occur in the web server. An attacker can exploit this by sending a POST request to the vulnerable PHP page. An attacker can elevate to root pe…
- CVE-2024-27565CRITICALCVSS 9.8EG 9.82024-03-05
A Server-Side Request Forgery (SSRF) in weixin.php of ChatGPT-wechat-personal commit a0857f6 allows attackers to force the application to make arbitrary requests.
- CVE-2024-23761CRITICALCVSS 9.8EG 9.82024-02-12
Server Side Template Injection in Gambio 4.9.2.0 allows attackers to run arbitrary code via crafted smarty email template.
- CVE-2023-42282CRITICALCVSS 9.8EG 9.82024-02-08
The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via isPublic.
- CVE-2024-0304CRITICALCVSS 9.8EG 9.82024-01-08
A vulnerability has been found in Youke365 up to 1.5.3 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /app/api/controller/collect.php. The manipulation of the argument url leads to server…
- CVE-2024-0303CRITICALCVSS 9.8EG 9.82024-01-08
A vulnerability, which was classified as critical, was found in Youke365 up to 1.5.3. Affected is an unknown function of the file /app/api/controller/caiji.php of the component Parameter Handler. The manipulation of the argument url leads …
- CVE-2023-51467CRITICALCVSS 9.8EG 9.82023-12-26
The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code
- CVE-2023-6974CRITICALCVSS 9.8EG 9.82023-12-20
A malicious user could use this issue to access internal HTTP(s) servers and in the worst case (ie: aws instance) it could be abuse to get a remote code execution on the victim machine.
- CVE-2023-6853CRITICALCVSS 9.8EG 9.82023-12-16
A vulnerability classified as critical was found in kalcaddle KodExplorer up to 4.51.03. Affected by this vulnerability is the function index of the file plugins/officeLive/app.php. The manipulation of the argument path leads to server-sid…
- CVE-2023-6852CRITICALCVSS 9.8EG 9.82023-12-16
A vulnerability classified as critical has been found in kalcaddle KodExplorer up to 4.51.03. Affected is an unknown function of the file plugins/webodf/app.php. The manipulation leads to server-side request forgery. It is possible to laun…
- CVE-2023-6849CRITICALCVSS 9.8EG 9.82023-12-16
A vulnerability was found in kalcaddle kodbox up to 1.48. It has been rated as critical. Affected by this issue is the function cover of the file plugins/fileThumb/app.php. The manipulation of the argument path leads to server-side request…
- CVE-2023-40630CRITICALCVSS 9.8EG 9.82023-12-14
Unauthenticated LFI/SSRF in JCDashboards component for Joomla.
- CVE-2023-48910CRITICALCVSS 9.8EG 9.82023-12-04
Microcks up to 1.17.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /jobs and /artifact/download. This vulnerability allows attackers to access network resources and sensitive information via a crafted GE…
- CVE-2023-48022CRITICALCVSS 9.8EG 9.82023-11-28
Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its documentation, is not intended for use …
- CVE-2023-46480CRITICALCVSS 9.8EG 9.82023-11-27
An issue in OwnCast v.0.1.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via the authHost parameter of the indieauth function.
- CVE-2023-5974CRITICALCVSS 9.8EG 9.82023-11-27
The WPB Show Core WordPress plugin through 2.2 is vulnerable to server-side request forgery (SSRF) via the `path` parameter.
- CVE-2023-48307CRITICALCVSS 9.8EG 9.82023-11-21
Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. Starting in version 1.13.0 and prior to version 2.2.8 and 3.3.0, an attacker can use an unprotected endpoint in the Mail app to perform a SSRF attack. Nextc…
- CVE-2023-48306CRITICALCVSS 9.8EG 9.82023-11-21
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.11, 26.0.6, and 27.1.0 of Nextcloud Server and starting in version 22.0.0 and prior to versions 22.2…
- CVE-2023-47121CRITICALCVSS 9.8EG 9.82023-11-10
Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, the embedding feature is susceptible to server side request for…
Map vulnerabilities like CWE-918 to your infrastructure
EchelonGraph correlates every CVE — across CWE-918 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →