CWE-918: Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

809
Total CVEs
169
Critical
305
High
7.2
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
121
2025
340
2024
157
2023
60
2022
53

Top Affected Vendors

1 Microsoft 16
2 Apache 16
3 Ibm 9
4 Sap 7
5 Gitlab 7
6 Agpt 5
7 Maccms 5
8 Craftcms 5
9 Langchain 4
10 Progress 4

All Server-Side Request Forgery (SSRF) CVEs (809)

CVE-2023-53893
6.5

Ateme TITAN File 3.9.12.4 contains an authenticated server-side request forgery vulnerability in the job callback URL parameter. Attackers with valid ...

Dec 15, 2025
CVE-2025-13378
6.5

This vulnerability allows unauthenticated attackers to perform Server-Side Request Forgery (SSRF) attacks through the AI ChatBot with ChatGPT and Cont...

Nov 27, 2025
CVE-2025-64525
6.5

Astro web framework versions 2.16.0 to 5.15.4 with on-demand rendering are vulnerable to header injection attacks. Attackers can manipulate x-forwarde...

Nov 13, 2025
CVE-2025-52186
6.5

This SSRF vulnerability in Lichess lila allows remote attackers to force the server to make HTTP requests to arbitrary internal or external URLs via t...

Nov 13, 2025
CVE-2025-60319
6.5

PerfreeBlog v4.0.11 contains a Server-Side Request Forgery vulnerability in the uploadAttachByUrl API endpoint that allows attackers to make unauthori...

Oct 30, 2025
CVE-2025-60540
6.5

karakeep versions v0.26.0 to v0.7.0 contain a Server-Side Request Forgery (SSRF) vulnerability that allows attackers to make unauthorized requests fro...

Oct 14, 2025
CVE-2025-57305
6.5

VitaraCharts 5.3.5 contains a Server-Side Request Forgery (SSRF) vulnerability in fileLoader.jsp that allows attackers to make arbitrary HTTP requests...

Oct 2, 2025
CVE-2025-57055
6.5

WonderCMS 3.5.0 contains a Server-Side Request Forgery (SSRF) vulnerability in its custom module installation feature. Authenticated administrators ca...

Sep 17, 2025
CVE-2025-9862
6.5

A Server-Side Request Forgery (SSRF) vulnerability in Ghost allows attackers to make the server send requests to internal resources that should not be...

Sep 17, 2025
CVE-2025-43763
6.5

A server-side request forgery (SSRF) vulnerability in Liferay Portal and DXP allows attackers to manipulate custom object attachment fields to make un...

Sep 9, 2025
CVE-2025-43747
6.5

This SSRF vulnerability in Liferay DXP allows attackers to bypass domain validation and make unauthorized server requests. Attackers can potentially a...

Aug 21, 2025
CVE-2025-51058
6.5

Bottinelli Informatical Vedo Suite 2024.17 has a Server-side Request Forgery (SSRF) vulnerability in its /api_vedo/video/preview endpoint. Remote auth...

Aug 6, 2025
CVE-2024-55399
6.5

This Server-Side Request Forgery (SSRF) vulnerability in 4C Strategies Exonaut allows attackers to make unauthorized requests from the vulnerable serv...

Aug 6, 2025
CVE-2025-50234
6.5

MCCMS v2.7.0 has a server-side request forgery (SSRF) vulnerability that allows attackers to make the application send requests to internal systems an...

Aug 6, 2025
CVE-2025-30679
6.5

A Server-Side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central's modOSCE component allows attackers to manipulate parameters to access...

Jun 17, 2025
CVE-2024-7073
6.5

This CVE describes a server-side request forgery (SSRF) vulnerability in multiple WSO2 products that allows unauthenticated attackers to manipulate se...

Jun 2, 2025
CVE-2025-1522
6.5

This CVE-2025-1522 vulnerability in PostHog allows authenticated attackers to perform Server-Side Request Forgery (SSRF) through the database_schema m...

Apr 23, 2025
CVE-2025-29453
6.5

This vulnerability in Personal Management System 1.4.65 allows remote attackers to access sensitive information through the my-contacts-settings compo...

Apr 17, 2025
CVE-2025-29449
6.5

A Server-Side Request Forgery (SSRF) vulnerability in twonav v2.1.18-20241105 allows remote attackers to access internal network resources and sensiti...

Apr 17, 2025
CVE-2025-29454
6.5

A Server-Side Request Forgery (SSRF) vulnerability in Personal Management System version 1.4.65 allows remote attackers to access internal network res...

Apr 17, 2025
CVE-2025-0188
6.5

A Server-Side Request Forgery (SSRF) vulnerability in gaizhenbiao/chuanhuchatgpt allows attackers to make the application send requests to internal sy...

Mar 20, 2025
CVE-2024-12775
6.5

This SSRF vulnerability in Dify AI allows attackers to make the server send unauthorized requests to internal or external systems using the server's n...

Mar 20, 2025
CVE-2025-27600
6.5

FastGPT's web crawling plugin lacks intranet IP verification, allowing attackers to make requests to internal network resources. This could expose pri...

Mar 6, 2025
CVE-2025-1211
6.5

This SSRF vulnerability in hackney versions before 1.21.0 allows attackers to bypass URL parsing and make requests to internal systems. It affects app...

Feb 11, 2025
CVE-2024-45206
6.5

This vulnerability in Veeam Service Provider Console allows attackers to make arbitrary HTTP requests to internal network resources, potentially expos...

Dec 4, 2024
CVE-2024-38645
6.5

This CVE describes a server-side request forgery (SSRF) vulnerability in QNAP Notes Station 3 that allows authenticated attackers to read application ...

Nov 22, 2024
CVE-2024-46947
6.5

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Northern.tech Mender that allows attackers to make unauthorized requests from...

Nov 8, 2024
CVE-2024-48107
6.5

SparkShop versions up to 1.1.7 contain a server-side request forgery (SSRF) vulnerability that allows attackers to make the server send requests to in...

Oct 28, 2024
CVE-2022-25777
6.5

CVE-2022-25777 is a Server-Side Request Forgery (SSRF) vulnerability in Mautic that allows authenticated users to read system files and access interna...

Sep 18, 2024
CVE-2024-22217
6.5

This Server-Side Request Forgery (SSRF) vulnerability in Terminalfour allows authenticated users to abuse specific features to make requests to intern...

Aug 15, 2024
CVE-2024-4260
6.5

This vulnerability in the Page Builder Gutenberg Blocks WordPress plugin allows high-privilege users (contributors or above) to perform Server-Side Re...

Jul 23, 2024
CVE-2022-0528
6.5

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the Uppy file uploader library. Attackers can exploit this to make the server...

Mar 3, 2022
CVE-2025-12375
6.4

This Server-Side Request Forgery (SSRF) vulnerability in the Printful Integration for WooCommerce WordPress plugin allows authenticated attackers with...

Feb 19, 2026
CVE-2025-67961
6.4

This Server-Side Request Forgery (SSRF) vulnerability in the WPO365 Login WordPress plugin allows attackers to make unauthorized requests from the vul...

Jan 22, 2026
CVE-2025-14443
6.4

This SSRF vulnerability in OpenShift's API server allows attackers to make the server send requests to internal network resources by manipulating imag...

Dec 16, 2025
CVE-2025-12800
6.4

The WP Shortcodes Plugin — Shortcodes Ultimate for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via the su_shortcode_csv_table func...

Nov 23, 2025
CVE-2025-12376
6.4

The Icon List Block WordPress plugin contains a Server-Side Request Forgery vulnerability that allows authenticated attackers with Subscriber-level ac...

Nov 18, 2025
CVE-2025-12962
6.4

The Local Syndication WordPress plugin has a Server-Side Request Forgery (SSRF) vulnerability that allows authenticated attackers with Contributor-lev...

Nov 18, 2025
CVE-2025-11917
6.4

The WPeMatico RSS Feed Fetcher plugin for WordPress has a Server-Side Request Forgery (SSRF) vulnerability that allows authenticated users with Subscr...

Nov 5, 2025
CVE-2025-12388
6.4

The B Carousel Block WordPress plugin up to version 1.1.5 contains a Server-Side Request Forgery (SSRF) vulnerability that allows authenticated attack...

Nov 5, 2025
CVE-2025-11361
6.4

The Gutenberg Essential Blocks WordPress plugin contains a Server-Side Request Forgery vulnerability that allows authenticated attackers with Author-l...

Oct 18, 2025
CVE-2025-58962
6.4

This Server-Side Request Forgery (SSRF) vulnerability in the Publitio WordPress plugin allows attackers to make unauthorized requests from the server ...

Sep 22, 2025
CVE-2025-58011
6.4

This Server-Side Request Forgery (SSRF) vulnerability in the Alex Content Mask WordPress plugin allows attackers to make unauthorized requests from th...

Sep 22, 2025
CVE-2025-7843
6.4

This SSRF vulnerability in the Auto Save Remote Images (Drafts) WordPress plugin allows authenticated attackers with Contributor-level access or highe...

Sep 10, 2025
CVE-2025-47437
6.4

This Server-Side Request Forgery (SSRF) vulnerability in LiteSpeed Cache allows attackers to make unauthorized requests from the vulnerable server to ...

Sep 9, 2025
CVE-2025-28987
6.4

This Server-Side Request Forgery (SSRF) vulnerability in the PressForward WordPress plugin allows attackers to make unauthorized requests from the ser...

Aug 14, 2025
CVE-2025-6729
6.4

The PayMaster for WooCommerce WordPress plugin contains a Server-Side Request Forgery (SSRF) vulnerability that allows authenticated attackers with Su...

Jul 4, 2025
CVE-2025-47484
6.4

This SSRF vulnerability in the Oliver Campion Display Remote Posts Block WordPress plugin allows attackers to make unauthorized requests from the serv...

May 7, 2025
CVE-2025-31527
6.4

This Server-Side Request Forgery (SSRF) vulnerability in the Kishan WP Link Preview WordPress plugin allows attackers to make the vulnerable server se...

Mar 31, 2025
CVE-2024-13856
6.4

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to perform Server-Side Request Forgery (SSRF) attacks t...

Mar 22, 2025

About Server-Side Request Forgery (SSRF) (CWE-918)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Our database tracks 809 CVEs classified as CWE-918, with 169 rated critical and 305 rated high severity. The average CVSS score for Server-Side Request Forgery (SSRF) vulnerabilities is 7.2.

External reference: View CWE-918 on MITRE CWE →

Monitor Server-Side Request Forgery (SSRF) Vulnerabilities

Get alerted when new Server-Side Request Forgery (SSRF) CVEs affect your infrastructure.

Start Monitoring Free