CWE-918: Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

810
Total CVEs
169
Critical
306
High
7.2
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
121
2025
340
2024
157
2023
60
2022
53

Top Affected Vendors

1 Microsoft 16
2 Apache 16
3 Ibm 9
4 Sap 7
5 Gitlab 7
6 Agpt 5
7 Maccms 5
8 Craftcms 5
9 Langchain 4
10 Progress 4

All Server-Side Request Forgery (SSRF) CVEs (810)

CVE-2024-13856
6.4

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to perform Server-Side Request Forgery (SSRF) attacks t...

Mar 22, 2025
CVE-2025-1662
6.4

The URL Media Uploader WordPress plugin has a Server-Side Request Forgery (SSRF) vulnerability that allows authenticated attackers with author-level p...

Feb 28, 2025
CVE-2025-1043
6.4

This Server-Side Request Forgery (SSRF) vulnerability in the Embed Any Document WordPress plugin allows authenticated attackers with Contributor acces...

Feb 20, 2025
CVE-2024-10814
6.4

The Code Embed WordPress plugin has a Server-Side Request Forgery vulnerability that allows authenticated attackers with contributor-level access or h...

Nov 9, 2024
CVE-2024-37157
6.4

This vulnerability in Discourse allows attackers to manipulate the FastImage library to redirect requests to internal Discourse IP addresses, potentia...

Jul 3, 2024
CVE-2024-4354
6.4

The TablePress WordPress plugin is vulnerable to Server-Side Request Forgery (SSRF) that allows authenticated attackers with author-level access or hi...

Jun 7, 2024
CVE-2026-3683
6.3

This vulnerability in bufanyun HotGo allows attackers to perform server-side request forgery (SSRF) attacks by manipulating the ImageTransferStorage f...

Mar 8, 2026
CVE-2026-3681
6.3

This vulnerability allows remote attackers to perform server-side request forgery (SSRF) attacks against welovemedia FFmate versions up to 2.0.15. Att...

Mar 7, 2026
CVE-2026-3052
6.3

This CVE describes a server-side request forgery (SSRF) vulnerability in DataLinkDC Dinky's Flink Proxy Controller. Attackers can exploit the proxyUba...

Feb 24, 2026
CVE-2026-2985
6.3

This CVE describes a server-side request forgery (SSRF) vulnerability in Tiandy Video Surveillance System version 7.17.0. Attackers can manipulate the...

Feb 23, 2026
CVE-2026-2945
6.3

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in JeecgBoot 3.9.0 that allows attackers to make the server send HTTP requests t...

Feb 22, 2026
CVE-2026-2654
6.3

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in huggingface smolagents 1.24.0. Attackers can exploit the LocalPythonExecutor ...

Feb 18, 2026
CVE-2026-2558
6.3

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in GeekAI versions up to 4.2.4. Attackers can manipulate the 'url' parameter in ...

Feb 16, 2026
CVE-2026-2532
6.3

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in lintsinghua DeepAudit versions up to 3.0.3. Attackers can exploit this vulner...

Feb 16, 2026
CVE-2026-1062
6.3

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in xiweicheng TMS up to version 2.28.0. Attackers can manipulate URL parameters ...

Jan 17, 2026
CVE-2025-15373
6.3

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in EyouCMS versions up to 1.7.7. Attackers can exploit the saveRemote function i...

Dec 31, 2025
CVE-2025-15098
6.3

This CVE describes a server-side request forgery (SSRF) vulnerability in YunaiV yudao-cloud's Business Process Management component. Attackers can man...

Dec 26, 2025
CVE-2025-67743
6.3

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Local Deep Research's download service. Attackers can submit malicious URLs t...

Dec 23, 2025
CVE-2025-14518
6.3

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in PowerJob's network request handler. Attackers can manipulate targetIp/targetP...

Dec 11, 2025
CVE-2025-14516
6.3

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the Yalantis uCrop Android library version 2.2.11. The vulnerability allows a...

Dec 11, 2025
CVE-2025-13809
6.3

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in orionsec's orion-ops software. Attackers can manipulate SSH connection parame...

Dec 1, 2025
CVE-2025-13796
6.3

This Server-Side Request Forgery (SSRF) vulnerability in deco-cx apps allows attackers to manipulate the AnalyticsScript function's URL parameter, for...

Dec 1, 2025
CVE-2025-13789
6.3

This CVE describes a server-side request forgery (SSRF) vulnerability in ZenTao's AI module. Attackers can exploit the makeRequest function in module/...

Nov 30, 2025
CVE-2025-13588
6.3

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in lKinderBueno Streamity Xtream IPTV Player versions up to 2.8. Attackers can e...

Nov 24, 2025
CVE-2025-13174
6.3

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the WeRSS we-mp-rss Webhook module. Attackers can manipulate the web_hook_url...

Nov 14, 2025
CVE-2025-10764
6.3

This vulnerability in SeriaWei ZKEACMS allows attackers to perform server-side request forgery (SSRF) attacks by manipulating the Data argument in the...

Sep 21, 2025
CVE-2025-10760
6.3

This CVE describes a server-side request forgery (SSRF) vulnerability in Harness 3.3.0 that allows attackers to manipulate URL parameters in the Looku...

Sep 21, 2025
CVE-2025-10410
6.3

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in SourceCodester Link Status Checker 1.0 where manipulation of the 'proxy' para...

Sep 14, 2025
CVE-2025-10391
6.3

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in CRMEB versions up to 5.6.1. Attackers can manipulate the push_token_url param...

Sep 14, 2025
CVE-2025-10329
6.3

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in cdevroe unmark up to version 1.9.3. Attackers can manipulate the 'url' parame...

Sep 12, 2025
CVE-2025-10211
6.3

This is a Server-Side Request Forgery (SSRF) vulnerability in ChanCMS 3.3.0 that allows attackers to manipulate the taskUrl parameter to make the serv...

Sep 10, 2025
CVE-2025-10096
6.3

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in SimStudioAI sim software up to version 1.0.0. Attackers can manipulate the fi...

Sep 8, 2025
CVE-2025-57818
6.3

Authenticated users of Firecrawl could exploit a server-side request forgery (SSRF) vulnerability in the webhook functionality to send POST requests w...

Aug 26, 2025
CVE-2025-9395
6.3

This vulnerability in wangsongyan wblog 0.0.1 allows remote attackers to perform server-side request forgery (SSRF) attacks through the RestorePost fu...

Aug 24, 2025
CVE-2024-39954
6.3

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the eventmesh-runtime module's WebhookUtil.java component. Attackers can expl...

Aug 20, 2025
CVE-2025-8529
6.3

This critical vulnerability in cloudfavorites favorites-web allows attackers to perform server-side request forgery (SSRF) attacks by manipulating the...

Aug 4, 2025
CVE-2025-8527
6.3

This critical vulnerability in Exrick xboot allows remote attackers to perform server-side request forgery (SSRF) attacks by manipulating the loginUrl...

Aug 4, 2025
CVE-2025-8228
6.3

This critical vulnerability in ChanCMS allows attackers to perform server-side request forgery (SSRF) by manipulating the targetUrl parameter in the g...

Jul 27, 2025
CVE-2025-7787
6.3

This critical Server-Side Request Forgery (SSRF) vulnerability in Xuxueli xxl-job allows attackers to make unauthorized requests from the vulnerable s...

Jul 18, 2025
CVE-2025-7759
6.3

This CVE-2025-7759 is a Server-Side Request Forgery (SSRF) vulnerability in thinkgem JeeSite's UEditor image grabber component. Attackers can manipula...

Jul 17, 2025
CVE-2025-7103
6.3

This critical Server-Side Request Forgery (SSRF) vulnerability in BoyunCMS allows attackers to make unauthorized requests from the vulnerable server t...

Jul 7, 2025
CVE-2025-6762
6.3

This critical vulnerability in diyhi bbs allows remote attackers to perform server-side request forgery (SSRF) by manipulating the Host header in the ...

Jun 27, 2025
CVE-2025-6517
6.3

This critical Server-Side Request Forgery (SSRF) vulnerability in Dromara MaxKey allows attackers to manipulate the Meta URL Handler to make unauthori...

Jun 23, 2025
CVE-2025-6142
6.3

This critical vulnerability in Intera InHire allows remote attackers to perform server-side request forgery (SSRF) by manipulating the '29chcotoo9' pa...

Jun 16, 2025
CVE-2025-5510
6.3

This critical SSRF vulnerability in quequnlong shiyi-blog allows attackers to make the server send unauthorized requests to internal or external syste...

Jun 3, 2025
CVE-2025-5327
6.3

This critical SSRF vulnerability in chshcms mccms 2.7 allows attackers to manipulate the 'pic' parameter to make the server send unauthorized requests...

May 29, 2025
CVE-2025-3412
6.3

This critical vulnerability in mymagicpower AIAS allows attackers to perform Server-Side Request Forgery (SSRF) by manipulating the 'url' parameter in...

Apr 8, 2025
CVE-2025-3254
6.3

This critical vulnerability in xujiangfei admintwo 1.0 allows remote attackers to perform server-side request forgery (SSRF) attacks by manipulating t...

Apr 4, 2025
CVE-2025-2997
6.3

This critical vulnerability in Youkefu 4.2.0 allows remote attackers to perform server-side request forgery (SSRF) attacks by manipulating the 'url' p...

Mar 31, 2025
CVE-2025-28093
6.3

ShopXO v6.4.0 contains a Server-Side Request Forgery (SSRF) vulnerability in its email settings functionality. This allows authenticated attackers to ...

Mar 28, 2025

About Server-Side Request Forgery (SSRF) (CWE-918)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Our database tracks 810 CVEs classified as CWE-918, with 169 rated critical and 306 rated high severity. The average CVSS score for Server-Side Request Forgery (SSRF) vulnerabilities is 7.2.

External reference: View CWE-918 on MITRE CWE →

Monitor Server-Side Request Forgery (SSRF) Vulnerabilities

Get alerted when new Server-Side Request Forgery (SSRF) CVEs affect your infrastructure.

Start Monitoring Free