CWE-918— Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.— MITRE CWE catalog
3,835 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-918page 6 of 77
- CVE-2021-40091CRITICALCVSS 9.8EG 9.82021-12-06
An SSRF issue was discovered in SquaredUp for SCOM 5.2.1.6654.
- CVE-2021-22049CRITICALCVSS 9.8EG 9.82021-11-24
The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forgery) vulnerability in the vSAN Web Client (vSAN UI) plug-in. A malicious actor with network access to port 443 on vCenter Server may exploit this issue by access…
- CVE-2021-39303CRITICALCVSS 9.8EG 9.82021-11-12
The server in Jamf Pro before 10.32.0 has an SSRF vulnerability, aka PI-006352. NOTE: Jamf Nation will also publish an article about this vulnerability.
- CVE-2021-22958CRITICALCVSS 9.8EG 9.82021-10-07
A Server-Side Request Forgery vulnerability was found in concrete5 < 8.5.5 that allowed a decimal notation encoded IP address to bypass the limitations in place for localhost allowing interaction with local services. Impact can vary depend…
- CVE-2021-39497CRITICALCVSS 9.8EG 9.82021-09-07
eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject a url to trigger blind SSRF via the saveRemote() function.
- CVE-2021-37353CRITICALCVSS 9.8EG 9.82021-08-13
Nagios XI Docker Wizard before version 1.1.3 is vulnerable to SSRF due to improper sanitation in table_population.php.
- CVE-2021-24472CRITICALCVSS 9.8EG 9.82021-08-02
The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functionality to unauthenticated users, sending requests to this proxy functionality will have the web server fetch and display t…
- CVE-2020-24142CRITICALCVSS 9.8EG 9.82021-07-07
Server-side request forgery in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker send crafted requests from the back-end server of a vulnerable web application via the njt-tk-download-video p…
- CVE-2021-35209CRITICALCVSS 9.8EG 9.82021-07-02
An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.x before 9.0.0 Patch 16. The value of the X-Host header overwrites the value of the Host header in proxied re…
- CVE-2021-31531CRITICALCVSS 9.8EG 9.82021-06-29
Zoho ManageEngine ServiceDesk Plus MSP before 10521 is vulnerable to Server-Side Request Forgery (SSRF).
- CVE-2021-32682CRITICALCVSS 9.8EG 9.82021-06-14
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerabilities can allow an attacker to execute arbitrary code and commands on the server hostin…
- CVE-2020-15377CRITICALCVSS 9.8EG 9.82021-06-09
Webtools in Brocade SANnav before version 2.1.1 allows unauthenticated users to make requests to arbitrary hosts due to a misconfiguration; this is commonly referred to as Server-Side Request Forgery (SSRF).
- CVE-2017-17674CRITICALCVSS 9.8EG 9.82021-05-19
BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be vulnerable to attacks such as system fingerprinting, internal port scanning, Server Side …
- CVE-2021-29145CRITICALCVSS 9.8EG 9.82021-04-29
A remote server side request forgery (SSRF) remote code execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6.9.5, 6.8.9, 6.7.14-HF1. Aruba has released patches for Aruba ClearPass Policy Manager th…
- CVE-2020-35313CRITICALCVSS 9.8EG 9.82021-04-20
A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remote attackers to execute arbitrary code via a crafted URL to the theme/plugin installer.
- CVE-2021-27905CRITICALCVSS 9.8EG 9.82021-04-13
The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter that is used to designate another ReplicationHandler on another Solr core to replicate ind…
- CVE-2021-1627CRITICALCVSS 9.8EG 9.82021-03-26
MuleSoft is aware of a Server Side Request Forgery vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. This affects: Mule 3.8.x,3.9.x,4.x runtime released before Febr…
- CVE-2020-23534CRITICALCVSS 9.8EG 9.82021-02-25
A server-side request forgery (SSRF) vulnerability in Upgrade.php of gopeak masterlab 2.1.5, via the 'source' parameter.
- CVE-2021-27670CRITICALCVSS 9.8EG 9.82021-02-25
Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.
- CVE-2020-35205CRITICALCVSS 9.8EG 9.82021-01-11
Server Side Request Forgery (SSRF) in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to scan internal ports and make outbound connections via the initFile.jsp file. NOTE: This vulnerability only affects…
- CVE-2020-35712CRITICALCVSS 9.8EG 9.82020-12-26
Esri ArcGIS Server before 10.8 is vulnerable to SSRF in some configurations.
- CVE-2020-28360CRITICALCVSS 9.8EG 9.82020-11-23
Insufficient RegEx in private-ip npm package v1.0.5 and below insufficiently filters reserved IP ranges resulting in indeterminate SSRF. An attacker can perform a large range of requests to ARIN reserved IP ranges, resulting in an indeterm…
- CVE-2020-24881CRITICALCVSS 9.8EG 9.82020-11-02
SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.
- CVE-2020-25466CRITICALCVSS 9.8EG 9.82020-10-23
A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.
- CVE-2020-27197CRITICALCVSS 9.8EG 9.82020-10-17
TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vend…
- CVE-2020-26948CRITICALCVSS 9.8EG 9.82020-10-10
Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter.
- CVE-2020-14056CRITICALCVSS 9.8EG 9.82020-07-01
Monsta FTP 2.10.1 or below is prone to a server-side request forgery vulnerability due to insufficient restriction of the web fetch functionality. This allows attackers to read arbitrary local files and interact with arbitrary third-party …
- CVE-2020-13484CRITICALCVSS 9.8EG 9.82020-06-24
Bitrix24 through 20.0.975 allows SSRF via an intranet IP address in the services/main/ajax.php?action=attachUrlPreview url parameter, if the destination URL hosts an HTML document containing '<meta name="og:image" content="' followed by an…
- CVE-2020-4101CRITICALCVSS 9.8EG 9.82020-06-11
"HCL Digital Experience is susceptible to Server Side Request Forgery."
- CVE-2020-6275CRITICALCVSS 9.8EG 9.82020-06-10
SAP Netweaver AS ABAP, versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, are vulnerable for Server Side Request Forgery Attack where in an attacker can use inappropriate path names containing malicious server names …
- CVE-2020-13226CRITICALCVSS 9.8EG 9.82020-05-20
WSO2 API Manager 3.0.0 does not properly restrict outbound network access from a Publisher node, opening up the possibility of SSRF to this node's entire intranet.
- CVE-2020-10980CRITICALCVSS 9.8EG 9.82020-04-08
GitLab EE/CE 8.0.rc1 to 12.9 is vulnerable to a blind SSRF in the FogBugz integration.
- CVE-2020-10956CRITICALCVSS 9.8EG 9.82020-03-27
GitLab 8.10 and later through 12.9 is vulnerable to an SSRF in a project import note feature.
- CVE-2019-11574CRITICALCVSS 9.8EG 9.82020-03-20
An issue was discovered in Simple Machines Forum (SMF) before release 2.0.17. There is SSRF related to Subs-Package.php and Subs.php because user-supplied data is used directly in curl calls.
- CVE-2020-8135CRITICALCVSS 9.8EG 9.82020-03-20
The uppy npm package < 1.9.3 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external network or otherwise interact with internal systems.
- CVE-2020-10077CRITICALCVSS 9.8EG 9.82020-03-13
GitLab EE 3.0 through 12.8.1 allows SSRF. An internal investigation revealed that a particular deprecated service was creating a server side request forgery risk.
- CVE-2020-8540CRITICALCVSS 9.8EG 9.82020-03-11
An XML external entity (XXE) vulnerability in Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted D…
- CVE-2019-12443CRITICALCVSS 9.8EG 9.82020-03-10
An issue was discovered in GitLab Community and Enterprise Edition 10.2 through 11.11. Multiple features contained Server-Side Request Forgery (SSRF) vulnerabilities caused by an insufficient validation to prevent DNS rebinding attacks.
- CVE-2020-10212CRITICALCVSS 9.8EG 9.82020-03-07
upload.php in Responsive FileManager 9.13.4 and 9.14.0 allows SSRF via the url parameter because file-extension blocking is mishandled and because it is possible for a DNS hostname to resolve to an internal IP address. For example, an SSRF…
- CVE-2020-8128CRITICALCVSS 9.8EG 9.82020-02-14
An unintended require and server-side request forgery vulnerabilities in jsreport version 2.5.0 and earlier allow attackers to execute arbitrary code.
- CVE-2020-3938CRITICALCVSS 9.8EG 9.82020-02-04
SysJust Syuan-Gu-Da-Shih, versions before 20191223, contain vulnerability of Request Forgery, allowing attackers to launch inquiries into network architecture or system files of the server via forged inquests.
- CVE-2013-4864CRITICALCVSS 9.8EG 9.82020-01-28
MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url parameter to cgi-bin/cmh/proxy.sh, related to a Server-Side Request Forgery (SSRF) issue.
- CVE-2019-5464CRITICALCVSS 9.8EG 9.82020-01-28
A flawed DNS rebinding protection issue was discovered in GitLab CE/EE 10.2 and later in the `url_blocker.rb` which could result in SSRF where the library is utilized.
- CVE-2019-16948CRITICALCVSS 9.8EG 9.82019-11-13
An SSRF issue was discovered in Enghouse Web Chat 6.1.300.31. In any POST request, one can replace the port number at WebServiceLocation=http://localhost:8085/UCWebServices/ with a range of ports to determine what is visible on the interna…
- CVE-2019-18394CRITICALCVSS 9.8EG 9.82019-10-24
A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrary HTTP GET requests.
- CVE-2019-18355CRITICALCVSS 9.8EG 9.82019-10-23
An SSRF issue was discovered in the legacy Web launcher in Thycotic Secret Server before 10.7.
- CVE-2019-17670CRITICALCVSS 9.8EG 9.82019-10-17
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs.
- CVE-2019-17669CRITICALCVSS 9.8EG 9.82019-10-17
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters.
- CVE-2019-13335CRITICALCVSS 9.8EG 9.82019-10-02
SalesAgility SuiteCRM 7.10.x 7.10.19 and 7.11.x before and 7.11.7 has SSRF.
- CVE-2019-15494CRITICALCVSS 9.8EG 9.82019-08-23
openITCOCKPIT before 3.7.1 allows SSRF, aka RVID 5-445b21.
Map vulnerabilities like CWE-918 to your infrastructure
EchelonGraph correlates every CVE — across CWE-918 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →