CWE-918: Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Yearly Trend
Top Affected Vendors
All Server-Side Request Forgery (SSRF) CVEs (815)
This critical SSRF vulnerability in chshcms mccms 2.7 allows attackers to manipulate the 'pic' parameter to make the server send unauthorized requests...
May 29, 2025This critical vulnerability in mymagicpower AIAS allows attackers to perform Server-Side Request Forgery (SSRF) by manipulating the 'url' parameter in...
Apr 8, 2025This critical vulnerability in xujiangfei admintwo 1.0 allows remote attackers to perform server-side request forgery (SSRF) attacks by manipulating t...
Apr 4, 2025This critical vulnerability in Youkefu 4.2.0 allows remote attackers to perform server-side request forgery (SSRF) attacks by manipulating the 'url' p...
Mar 31, 2025ShopXO v6.4.0 contains a Server-Side Request Forgery (SSRF) vulnerability in its email settings functionality. This allows authenticated attackers to ...
Mar 28, 2025This critical vulnerability in zj1983 zz software allows attackers to perform Server-Side Request Forgery (SSRF) attacks by manipulating the 'url' par...
Mar 3, 2025This critical SSRF vulnerability in zj1983 zz software allows attackers to manipulate the 'url' parameter in the sendNotice function to make the serve...
Mar 2, 2025This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in YouDianCMS 7 that allows attackers to manipulate the curl_exec function to ma...
Aug 1, 2024This CVE describes a critical Server-Side Request Forgery (SSRF) vulnerability in OTCMS 6.72. Attackers can exploit the UseCurl function in /admin/inf...
Mar 25, 2023This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Adobe ColdFusion that allows high-privilege authenticated attackers to force ...
Jul 8, 2025This vulnerability in lucy-xss-filter allows attackers to trigger server-side HEAD requests to arbitrary URLs when specific security listeners are ena...
Jan 16, 2026WeKnora versions before 0.2.12 have an SSRF vulnerability in the 'Import document via URL' feature that allows attackers to bypass URL validation thro...
Mar 7, 2026This vulnerability allows unauthenticated attackers to register FASP accounts with attacker-controlled base URLs that point to internal systems, forci...
Feb 24, 2026The WP Crontrol WordPress plugin versions 1.17.0 to 1.19.1 contain a blind Server-Side Request Forgery (SSRF) vulnerability that allows authenticated ...
Aug 22, 2025Mailpit versions before 1.29.2 contain a Server-Side Request Forgery (SSRF) vulnerability in the Link Check API that allows attackers to make the serv...
Feb 26, 2026DoraCMS versions 3.1 and earlier contain a server-side request forgery (SSRF) vulnerability in the UEditor remote image fetch feature. This allows att...
Feb 10, 2026CVE-2026-25765 is a Server-Side Request Forgery (SSRF) vulnerability in Faraday HTTP client library versions before 2.14.1. Attackers can exploit prot...
Feb 9, 2026The LangSmith SDK distributed tracing feature is vulnerable to Server-Side Request Forgery (SSRF) via malicious HTTP headers. Attackers can inject arb...
Feb 9, 2026CVE-2026-25904 is a Server-Side Request Forgery (SSRF) vulnerability in Pydantic-AI MCP Run Python tool's Deno sandbox configuration. The overly permi...
Feb 9, 2026Mailpit versions before 1.28.3 are vulnerable to Server-Side Request Forgery (SSRF) through the HTML Check feature. When analyzing HTML emails, the sy...
Jan 19, 2026CVE-2026-22772 is a server-side request forgery (SSRF) vulnerability in Fulcio's MetaIssuer URL validation. Attackers can bypass validation using unan...
Jan 12, 2026Mailpit versions 1.28.0 and below have a Server-Side Request Forgery (SSRF) vulnerability in the /proxy endpoint that allows attackers to make HTTP GE...
Jan 8, 2026A half-blind SSRF vulnerability in kube-controller-manager's Portworx StorageClass allows authorized Kubernetes users to access unprotected endpoints ...
Dec 14, 2025This vulnerability allows unauthenticated attackers to perform blind server-side request forgery (SSRF) attacks through the Feedzy RSS Aggregator Word...
Dec 11, 2025The WP Migrate Lite plugin for WordPress has a blind SSRF vulnerability that allows unauthenticated attackers to make arbitrary web requests from the ...
Nov 18, 2025An unauthenticated SSRF vulnerability in Halo CMS 2.21 allows attackers to make the server send HTTP requests to arbitrary URLs, including internal ne...
Oct 29, 2025An unauthenticated server-side request forgery vulnerability in MedDream PACS Premium allows attackers to make arbitrary HTTP requests from the vulner...
Jul 28, 2025This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Akamai CloudTest. It allows attackers to make unauthorized requests from the ...
Jun 30, 2025This vulnerability in MLflow's gateway_proxy_handler allows attackers to bypass path validation, potentially leading to server-side request forgery (S...
Jun 23, 2025This CVE describes a Server-Side Request Forgery (SSRF) vulnerability that allows authenticated attackers to make the server send requests to internal...
Aug 12, 2025This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the worldquant-miner software up to version 1.0.9. Attackers can exploit this...
Feb 19, 2026This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Tomofun Furbo 360 and Furbo Mini pet cameras via their GATT Interface URL Han...
Oct 12, 2025This CVE describes a server-side request forgery (SSRF) vulnerability in Tomofun Furbo 360 pet cameras up to firmware version FB0035_FW_036. Attackers...
Oct 12, 2025This CVE describes a server-side request forgery (SSRF) vulnerability in the Orbit Fox WordPress plugin. Attackers can force the WordPress server to m...
Oct 24, 2025This Server-Side Request Forgery (SSRF) vulnerability in the kodeshpa Simplified WordPress plugin allows attackers to make the vulnerable server send ...
Aug 14, 2025This Server-Side Request Forgery vulnerability in the Featured Image Plus WordPress plugin allows authenticated administrators to make arbitrary web r...
Jul 23, 2025This SSRF vulnerability in Ivanti Connect Secure and Policy Secure allows authenticated administrators to make requests to internal network services f...
Jul 8, 2025This vulnerability in GeoServer allows attackers to upload arbitrary files via the Coverage REST API without proper URL validation. Attackers can expl...
Jun 10, 2025The Ninja Forms Webhooks plugin for WordPress has a Server-Side Request Forgery (SSRF) vulnerability that allows authenticated administrators to make ...
May 14, 2025This Server-Side Request Forgery (SSRF) vulnerability in WPWebinarSystem WebinarPress allows attackers to make unauthorized requests from the vulnerab...
May 7, 2025MrDoc v0.95 and earlier contains a Server-Side Request Forgery (SSRF) vulnerability in the validate_url function that allows attackers to make unautho...
May 6, 2025The Gravity Forms WebHooks plugin for WordPress has a Server-Side Request Forgery vulnerability that allows authenticated administrators to make arbit...
May 1, 2025This vulnerability allows authenticated WordPress administrators to perform Server-Side Request Forgery (SSRF) attacks through the Uncanny Automator p...
Mar 12, 2025This is a Server-Side Request Forgery (SSRF) vulnerability in ShopXO's Uploader.php component. Attackers can manipulate the 'source' parameter to make...
Jul 5, 2024IBM Concert versions 1.0.0 through 2.1.0 contain a server-side request forgery (SSRF) vulnerability that allows authenticated attackers to make unauth...
Feb 17, 2026This vulnerability allows authenticated GitLab users with specific permissions to make unauthorized requests to internal network services through the ...
Feb 11, 2026The Fluent Forms Pro Add On Pack plugin for WordPress has a Server-Side Request Forgery vulnerability that allows authenticated users with Subscriber-...
Feb 9, 2026This Server-Side Request Forgery (SSRF) vulnerability in the Grand Blog WordPress theme allows attackers to make the vulnerable server send unauthoriz...
Feb 3, 2026This Server-Side Request Forgery (SSRF) vulnerability in the PhotoMe WordPress theme allows attackers to make unauthorized requests from the vulnerabl...
Jan 22, 2026This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the Electrician - Electrical Service WordPress theme. Attackers can exploit t...
Jan 22, 2026About Server-Side Request Forgery (SSRF) (CWE-918)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Our database tracks 815 CVEs classified as CWE-918, with 170 rated critical and 310 rated high severity. The average CVSS score for Server-Side Request Forgery (SSRF) vulnerabilities is 7.2.
External reference: View CWE-918 on MITRE CWE →
Monitor Server-Side Request Forgery (SSRF) Vulnerabilities
Get alerted when new Server-Side Request Forgery (SSRF) CVEs affect your infrastructure.
Start Monitoring Free