CWE-918: Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Yearly Trend
Top Affected Vendors
All Server-Side Request Forgery (SSRF) CVEs (808)
This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the Darren Cooney Instant Images WordPress plugin. It allows authenticated at...
Nov 22, 2023This Server-Side Request Forgery (SSRF) vulnerability in Deskpro Support Desk allows attackers to craft malicious URLs that trick the server into maki...
Jul 21, 2023CVE-2023-36925 is a server-side request forgery (SSRF) vulnerability in SAP Solution Manager Diagnostics Agent version 7.20 that allows unauthenticate...
Jul 11, 2023This vulnerability in the Import Export All WordPress Images, Users & Post Types plugin allows administrators to perform Blind Server-Side Request For...
Jun 27, 2022CVE-2022-24871 is a server-side request forgery (SSRF) vulnerability in Shopware's Admin SDK functionality that allows attackers to read or update int...
Apr 20, 2022CVE-2021-33581 is a Server-Side Request Forgery (SSRF) vulnerability in MashZone NextGen that allows attackers to interact with arbitrary TCP services...
Mar 30, 2022CVE-2021-4075 is a Server-Side Request Forgery (SSRF) vulnerability in Snipe-IT that allows attackers to make the application send unauthorized reques...
Dec 6, 2021This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Emissary, a P2P-based workflow engine. Attackers can exploit the RegisterPeer...
Jul 2, 2021CVE-2021-21311 is a server-side request forgery (SSRF) vulnerability in Adminer database management software that allows attackers to make unauthorize...
Feb 11, 2021StorageGRID versions with Single Sign-on enabled and configured to use Microsoft Entra ID are vulnerable to Server-Side Request Forgery (SSRF). This a...
Feb 18, 2026This CVE describes a server-side request forgery (SSRF) vulnerability in TrustTunnel VPN software that allows attackers to bypass private network rest...
Jan 29, 2026A Server-Side Request Forgery (SSRF) vulnerability in vLLM's MediaConnector class allows attackers to bypass host restrictions and make the server sen...
Jan 27, 2026This Server-Side Request Forgery (SSRF) vulnerability in Microsoft Office SharePoint allows authenticated attackers to make unauthorized requests from...
Aug 12, 2025A Server-Side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (SaaS) allows attackers to manipulate parameters to access internal sys...
Jun 17, 2025FreshRSS versions before 1.26.2 contain an authentication bypass vulnerability when using HTTP auth via reverse proxy. Attackers with an account on th...
Jun 4, 2025This vulnerability allows authenticated low-privileged users in WhatsUp Gold to perform server-side request forgery (SSRF) attacks. By chaining this S...
Jun 25, 2024This Server-Side Request Forgery (SSRF) vulnerability in the Spectra WordPress plugin allows attackers to make unauthorized requests from the vulnerab...
Mar 28, 2024A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central allows an authenticated attacker to make requests to...
Jan 23, 2024This Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates plugin allows attackers to make unauthorized requests from...
Dec 7, 2023This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the WordPress Shortcodes Ultimate plugin. It allows attackers to make the vul...
Nov 13, 2023This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Apache XML Graphics Batik version 1.16. A malicious SVG file can trigger the ...
Aug 22, 2023This CVE describes a server-side request forgery (SSRF) vulnerability in IBM Watson Machine Learning on Cloud Pak for Data. An authenticated attacker ...
Apr 27, 2023This vulnerability in Veritas NetBackup allows authenticated attackers on NetBackup Clients to remotely read arbitrary files, perform Server-Side Requ...
Jul 28, 2022This SSRF vulnerability in Craft CMS allows attackers with GraphQL asset management permissions to force the server to fetch content from arbitrary in...
Jan 5, 2026This vulnerability in grist-core allows authenticated users to perform server-side request forgery (SSRF) attacks. Any user with document access can e...
Nov 13, 2025This SSRF vulnerability in the Real Cookie Banner WordPress plugin allows authenticated administrators to make arbitrary HTTP requests from the web se...
Oct 24, 2025The WP Scraper WordPress plugin contains a Server-Side Request Forgery (SSRF) vulnerability that allows authenticated administrators to make arbitrary...
Oct 11, 2025This vulnerability allows admin-level attackers in Vasion Print (formerly PrinterLogic) to exploit improper input validation in printer configuration ...
Sep 29, 2025This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in multiple Ivanti security products that allows authenticated administrators to...
Sep 9, 2025This Server-Side Request Forgery (SSRF) vulnerability in QuantumCloud SEO Help WordPress plugin allows attackers to make the vulnerable server send HT...
Apr 9, 2025This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Dell SmartFabric OS10 Software. A high-privileged attacker with remote access...
Mar 17, 2025This Server-Side Request Forgery vulnerability in Emlog Pro allows attackers to make the vulnerable server send requests to internal network resources...
Feb 26, 2025This SSRF vulnerability in Dell PowerProtect DD allows remote attackers with high privileges to make the server send requests to internal systems, pot...
Jun 26, 2024This vulnerability allows unauthorized external users to perform Server Side Request Forgery (SSRF) attacks through GitLab's CI Lint API. Attackers ca...
Dec 13, 2021CVE-2021-22175 is a server-side request forgery (SSRF) vulnerability in GitLab that allows unauthenticated attackers to make requests to internal netw...
Jun 11, 2021This vulnerability in Doccano's annotation tools allows remote attackers to escalate privileges via the model_attribs parameter. It affects users of D...
Sep 23, 2024This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in ZITADEL's Action V2 feature that allows attackers to make ZITADEL send reques...
Feb 26, 2026This vulnerability in Astro web framework versions 9.0.0-9.5.3 allows attackers to bypass image domain restrictions when the inferSize option is enabl...
Feb 26, 2026Payload CMS versions before 3.75.0 contain a Server-Side Request Forgery (SSRF) vulnerability in external file upload functionality. Authenticated use...
Feb 24, 2026This CVE describes a Server-Side Request Forgery (SSRF) bypass vulnerability in Craft CMS. The SSRF validation in GraphQL Asset mutations fails to pro...
Feb 24, 2026This SSRF vulnerability in Azure DevOps Server allows authenticated attackers to make the server send requests to internal systems, potentially access...
Feb 10, 2026This vulnerability in Craft CMS allows authenticated attackers with permission to use the save_images_Asset GraphQL mutation to bypass hostname valida...
Feb 9, 2026This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Craft CMS where attackers can bypass SSRF protections by exploiting HTTP redi...
Feb 9, 2026This vulnerability allows attackers to bypass IP address blocklists in Craft CMS by using alternative IP notations (hexadecimal, mixed) that aren't re...
Feb 9, 2026This vulnerability allows authenticated attackers with low-level privileges in Hubert Imoveis e Administracao Ltda Hub v2.0 to access other users' inf...
Jan 13, 2026Miniflux 2's media proxy endpoint can be abused by authenticated users to perform Server-Side Request Forgery (SSRF), allowing attackers to make the s...
Jan 8, 2026Knowage versions before 8.1.37 have a blind server-side request forgery vulnerability that allows attackers to send requests to arbitrary internal hos...
Jan 7, 2026A Blind Server-Side Request Forgery vulnerability in evershop allows unauthenticated attackers to force the server to make HTTP requests to arbitrary ...
Jan 5, 2026Parse Server's Instagram authentication adapter allows attackers to specify custom API URLs, enabling Server-Side Request Forgery (SSRF) attacks. This...
Dec 16, 2025Ateme TITAN File 3.9.12.4 contains an authenticated server-side request forgery vulnerability in the job callback URL parameter. Attackers with valid ...
Dec 15, 2025About Server-Side Request Forgery (SSRF) (CWE-918)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Our database tracks 808 CVEs classified as CWE-918, with 168 rated critical and 305 rated high severity. The average CVSS score for Server-Side Request Forgery (SSRF) vulnerabilities is 7.2.
External reference: View CWE-918 on MITRE CWE →
Monitor Server-Side Request Forgery (SSRF) Vulnerabilities
Get alerted when new Server-Side Request Forgery (SSRF) CVEs affect your infrastructure.
Start Monitoring Free