CWE-918— Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.— MITRE CWE catalog
3,835 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-918page 7 of 77
- CVE-2019-0345CRITICALCVSS 9.8EG 9.82019-08-14
A remote unauthenticated attacker can abuse a web service in SAP NetWeaver Application Server for Java (Administrator System Overview), versions 7.30, 7.31, 7.40, 7.50, by sending a specially crafted XML file and trick the application serv…
- CVE-2019-14255CRITICALCVSS 9.8EG 9.82019-08-08
A Server Side Request Forgery (SSRF) vulnerability in go-camo up to version 1.1.4 allows a remote attacker to perform HTTP requests to internal endpoints.
- CVE-2019-14704CRITICALCVSS 9.8EG 9.82019-08-06
An SSRF issue was discovered in HTTPD on MicroDigital N-series cameras with firmware through 6400.0.8.5 via FTP commands following a newline character in the uploadfile field.
- CVE-2019-9827CRITICALCVSS 9.8EG 9.82019-07-03
Hawt Hawtio through 2.5.0 is vulnerable to SSRF, allowing a remote attacker to trigger an HTTP request from an affected server to an arbitrary host via the initial /proxy/ substring of a URI.
- CVE-2019-12852CRITICALCVSS 9.8EG 9.82019-07-03
An SSRF attack was possible on a JetBrains YouTrack server. The issue (1 of 2) was fixed in JetBrains YouTrack 2018.4.49168.
- CVE-2018-17198CRITICALCVSS 9.8EG 9.82019-05-28
Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsupported versions relies on Java SAX Parser to implement its XML-RPC interface and by default that parser supports external …
- CVE-2019-11066CRITICALCVSS 9.8EG 9.82019-05-10
openid.php in LightOpenID through 1.3.1 allows SSRF via a crafted OpenID 2.0 assertion request using the HTTP GET method.
- CVE-2019-11565CRITICALCVSS 9.8EG 9.82019-04-27
Server Side Request Forgery (SSRF) exists in the Print My Blog plugin before 1.6.7 for WordPress via the site parameter.
- CVE-2019-4203CRITICALCVSS 9.8EG 9.82019-04-15
IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal can be exploited by app developers to download arbitrary files from the host OS and potentially carry out SSRF attacks. IBM X-Force ID: 159124.
- CVE-2019-3395CRITICALCVSS 9.8EG 9.82019-03-25
The WebDAV endpoint in Atlassian Confluence Server and Data Center before version 6.6.7 (the fixed version for 6.6.x), from version 6.7.0 before 6.8.5 (the fixed version for 6.8.x), and from version 6.9.0 before 6.9.3 (the fixed version fo…
- CVE-2018-20596CRITICALCVSS 9.8EG 9.82018-12-30
Jspxcms v9.0.0 allows SSRF.
- CVE-2018-18753CRITICALCVSS 9.8EG 9.82018-10-29
Typecho V1.1 allows remote attackers to send shell commands via base64-encoded serialized data, as demonstrated by SSRF.
- CVE-2018-14728CRITICALCVSS 9.8EG 9.82018-08-03
upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.
- CVE-2018-14514CRITICALCVSS 9.8EG 9.82018-07-23
An SSRF vulnerability was discovered in idreamsoft iCMS V7.0.9 that allows attackers to read sensitive files, access an intranet, or possibly have unspecified other impact.
- CVE-2018-0403CRITICALCVSS 9.8EG 9.82018-07-18
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to retrieve a cleartext password. Cisco Bug IDs: CSCvg71040.
- CVE-2018-0399CRITICALCVSS 9.8EG 9.82018-07-18
Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to retrieve a cleartext password from an affected system. Cisco Bug IDs: CSCvg71044.
- CVE-2018-0398CRITICALCVSS 9.8EG 9.82018-07-18
Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack. Cisco Bug IDs: CSCvg71018.
- CVE-2018-12571CRITICALCVSS 9.8EG 9.82018-07-05
uniquesig0/InternalSite/InitParams.aspx in Microsoft Forefront Unified Access Gateway 2010 allows remote attackers to trigger outbound DNS queries for arbitrary hosts via a comma-separated list of URLs in the orig_url parameter, possibly c…
- CVE-2018-12678CRITICALCVSS 9.8EG 9.82018-06-22
Portainer before 1.18.0 supports unauthenticated requests to the websocket endpoint with an unvalidated id query parameter for the /websocket/exec endpoint, which allows remote attackers to bypass intended access restrictions or conduct SS…
- CVE-2018-11586CRITICALCVSS 9.8EG 9.82018-06-05
XML external entity (XXE) vulnerability in api/rest/status in SearchBlox 8.6.7 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.
- CVE-2018-11031CRITICALCVSS 9.8EG 9.82018-05-14
application/home/controller/debug.php in PHPRAP 1.0.4 through 1.0.8 has SSRF via the /debug URI, as demonstrated by an api[url]=file:////etc/passwd&api[method]=get POST request.
- CVE-2018-9919CRITICALCVSS 9.8EG 9.82018-05-02
A web-accessible backdoor, with resultant SSRF, exists in Tp-shop 2.0.5 through 2.0.8, which allows remote attackers to obtain sensitive information, attack intranet hosts, or possibly trigger remote command execution, because /vendor/phpd…
- CVE-2018-8939CRITICALCVSS 9.8EG 9.82018-05-01
An SSRF issue was discovered in NmAPI.exe in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can submit specially crafted requests via the NmAPI executable to (1) gain unauthorized access to the WhatsUp Gold system, (2) obtain i…
- CVE-2017-14323CRITICALCVSS 9.8EG 9.82018-04-10
SSRF (Server Side Request Forgery) in getRemoteImage.php in Ueditor in Onethink V1.0 and V1.1 allows remote attackers to obtain sensitive information, attack intranet hosts, or possibly trigger remote command execution via the upfile param…
- CVE-2017-16614CRITICALCVSS 9.8EG 9.82018-03-30
SSRF (Server Side Request Forgery) in tpshop 2.0.5 and 2.0.6 allows remote attackers to obtain sensitive information, attack intranet hosts, or possibly trigger remote command execution via the plugins/payment/weixin/lib/WxPay.tedatac.php …
- CVE-2014-3990CRITICALCVSS 9.8EG 9.82018-03-20
The Cart::getProducts method in system/library/cart.php in OpenCart 1.5.6.4 and earlier allows remote attackers to conduct server-side request forgery (SSRF) attacks or possibly conduct XML External Entity (XXE) attacks and execute arbitra…
- CVE-2018-7667CRITICALCVSS 9.8EG 9.82018-03-05
Adminer through 4.3.1 has SSRF via the server parameter.
- CVE-2017-1000237CRITICALCVSS 9.8EG 9.82017-11-17
I, Librarian version <=4.6 & 4.7 is vulnerable to Server-Side Request Forgery in the ajaxsupplement.php resulting in the attacker being able to reset any user's password.
- CVE-2017-0907CRITICALCVSS 9.8EG 9.82017-11-13
The Recurly Client .NET Library before 1.0.1, 1.1.10, 1.2.8, 1.3.2, 1.4.14, 1.5.3, 1.6.2, 1.7.1, 1.8.1 is vulnerable to a Server-Side Request Forgery vulnerability due to incorrect use of "Uri.EscapeUriString" that could result in compromi…
- CVE-2017-0906CRITICALCVSS 9.8EG 9.82017-11-13
The Recurly Client Python Library before 2.0.5, 2.1.16, 2.2.22, 2.3.1, 2.4.5, 2.5.1, 2.6.2 is vulnerable to a Server-Side Request Forgery vulnerability in the "Resource.get" method that could result in compromise of API keys or other criti…
- CVE-2017-0905CRITICALCVSS 9.8EG 9.82017-11-13
The Recurly Client Ruby Library before 2.0.13, 2.1.11, 2.2.5, 2.3.10, 2.4.11, 2.5.4, 2.6.3, 2.7.8, 2.8.2, 2.9.2, 2.10.4, 2.11.3 is vulnerable to a Server-Side Request Forgery vulnerability in the "Resource#find" method that could result in…
- CVE-2017-0889CRITICALCVSS 9.8EG 9.82017-11-13
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Paperclip::UriAdapter class. Attackers may be able to access information about internal network resources.
- CVE-2017-9458CRITICALCVSS 9.8EG 9.82017-09-07
XML external entity (XXE) vulnerability in the GlobalProtect internal and external gateway interface in Palo Alto Networks PAN-OS before 6.1.18, 7.0.x before 7.0.17, 7.1.x before 7.1.12, and 8.0.x before 8.0.3 allows remote attackers to ob…
- CVE-2004-2061CRITICALCVSS 9.8EG 9.82004-07-27
RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) http://, (2) ftp://, or (3) file:// URL.
- CVE-2002-1484CRITICALCVSS 9.8EG 9.82003-04-22
DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other systems (port scan) via a request for a URL that specifies the target IP address and port, …
- CVE-2024-41651CRITICALCVSS 8.1EG 9.82024-08-12
An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade functionality. NOTE: this is disputed by multiple parties, who report that exploitation requires that an attacker be able t…
- CVE-2023-0574CRITICALCVSS 6.8EG 9.82023-02-09
Server-Side Request Forgery (SSRF), Improperly Controlled Modification of Dynamically-Determined Object Attributes, Improper Restriction of Excessive Authentication Attempts vulnerability in YugaByte, Inc. Yugabyte Managed allows Accessing…
- CVE-2022-36376CRITICALCVSS 6.8EG 9.82022-09-09
Server-Side Request Forgery (SSRF) vulnerability in Rank Math SEO plugin <= 1.0.95 at WordPress.
- CVE-2023-1634CRITICALCVSS 6.3EG 9.82023-03-25
A vulnerability was found in OTCMS 6.72. It has been classified as critical. Affected is the function UseCurl of the file /admin/info_deal.php of the component URL Parameter Handler. The manipulation leads to server-side request forgery. I…
- CVE-2026-69435CRITICALCVSS 9.6EG 9.62026-10-08
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
- CVE-2026-82000CRITICALCVSS 9.6EG 9.62026-09-22
Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal …
- CVE-2026-61559CRITICALCVSS 9.6EG 9.62026-09-15
`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1.27, when the environment variable `ENABLE_DYNAMIC_API_URL=true` is set, the server reads the `X-GitLab-API-URL` HTTP r…
- CVE-2026-12944CRITICALCVSS 9.6EG 9.62026-09-14
IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports. This enables: (1) AWS credential t…
- CVE-2026-77822CRITICALCVSS 9.6EG 9.62026-09-04
IBM ContextForge MCP Gateway could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery via DNS rebinding.
- CVE-2026-75871CRITICALCVSS 9.6EG 9.62026-08-27
GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.10 to 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2 that could have allowed an authenticated user with Duo Agent Platfo…
- CVE-2026-12564CRITICALCVSS 9.6EG 9.62026-08-18
A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-con…
- CVE-2026-70332CRITICALCVSS 9.6EG 9.62026-08-06
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-12605CRITICALCVSS 9.6EG 9.62026-08-06
In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeov…
- CVE-2026-54725CRITICALCVSS 9.6EG 9.62026-07-31
vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, Mut…
- CVE-2026-48259CRITICALCVSS 9.6EG 9.62026-07-14
Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could leverage this vulnerability to iss…
Map vulnerabilities like CWE-918 to your infrastructure
EchelonGraph correlates every CVE — across CWE-918 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →