CWE-918: Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Yearly Trend
Top Affected Vendors
All Server-Side Request Forgery (SSRF) CVEs (816)
This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the Electrician - Electrical Service WordPress theme. Attackers can exploit t...
Jan 22, 2026This Server-Side Request Forgery (SSRF) vulnerability in Microsoft Office SharePoint allows authenticated attackers to make the server send requests t...
Jan 13, 2026This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the WordPress & WooCommerce Scraper Plugin, Import Data from Any Site. It all...
Dec 31, 2025This Server-Side Request Forgery (SSRF) vulnerability in the LMPixels Kerge WordPress theme allows attackers to make unauthorized requests from the vu...
Dec 16, 2025The Responsive Lightbox & Gallery WordPress plugin has a Server-Side Request Forgery vulnerability that allows authenticated attackers with Author-lev...
Nov 19, 2025IBM Concert versions 1.0.0 through 2.0.0 contain a server-side request forgery (SSRF) vulnerability that allows authenticated attackers to make unauth...
Oct 28, 2025This Server-Side Request Forgery (SSRF) vulnerability in Silencesoft RSS Reader allows attackers to make the vulnerable server send unauthorized reque...
Sep 26, 2025This Server-Side Request Forgery (SSRF) vulnerability in BdThemes ZoloBlocks WordPress plugin allows attackers to make the vulnerable server send unau...
Sep 26, 2025The Snow Monkey WordPress theme contains a Server-Side Request Forgery (SSRF) vulnerability that allows unauthenticated attackers to make arbitrary we...
Sep 26, 2025This Server-Side Request Forgery (SSRF) vulnerability in the DriCub WordPress theme allows attackers to make unauthorized requests from the vulnerable...
Sep 22, 2025This Server-Side Request Forgery (SSRF) vulnerability in the Exit Intent Popup WordPress plugin allows attackers to make unauthorized requests from th...
Sep 3, 2025IBM Edge Application Manager 4.5 contains a server-side request forgery (SSRF) vulnerability that allows authenticated attackers to make unauthorized ...
Aug 20, 2025Omnissa Workspace ONE UEM contains a Server-Side Request Forgery (SSRF) vulnerability that allows authenticated users to make the server send requests...
Aug 11, 2025This Server-Side Request Forgery (SSRF) vulnerability in Md Yeasin Ul Haider URL Shortener allows attackers to make the vulnerable server send unautho...
Jul 4, 2025Keyoti SearchUnit versions before 9.0.0 are vulnerable to Server-Side Request Forgery (SSRF) in two specific endpoints. Attackers can force the server...
Jun 10, 2025This Server-Side Request Forgery (SSRF) vulnerability in the Wbcom Designs Activity Link Preview For BuddyPress WordPress plugin allows attackers to m...
May 7, 2025This SSRF vulnerability in the Photography WordPress theme allows attackers to make the server send unauthorized requests to internal systems. It affe...
Apr 15, 2025OneNav 1.1.0 contains a Server-Side Request Forgery (SSRF) vulnerability in custom headers functionality. This allows attackers to make unauthorized r...
Mar 28, 2025This vulnerability in the Responsive Plus WordPress plugin allows authenticated attackers with contributor-level access or higher to perform Server-Si...
Feb 15, 2025IBM Aspera Shares versions 1.9.0 through 1.10.0 PL6 contain a server-side request forgery (SSRF) vulnerability that allows authenticated attackers to ...
Feb 5, 2025This Server-Side Request Forgery (SSRF) vulnerability in the Traveler Layout Essential For Elementor WordPress plugin allows attackers to make unautho...
Feb 3, 2025The Multiple Page Generator Plugin (MPG) for WordPress versions up to 4.0.5 contains a Server-Side Request Forgery (SSRF) vulnerability in the 'mpg_do...
Jan 26, 2025This Server-Side Request Forgery (SSRF) vulnerability in the Pixelcurve Edubin WordPress theme allows attackers to make unauthorized requests from the...
Aug 1, 2024Canarytokens.org had a blind Server-Side Request Forgery (SSRF) vulnerability in its webhook alert feature that allowed attackers to map internal netw...
Jul 23, 2024This SSRF vulnerability in Fluid Topics allows authenticated users to force the server to make arbitrary HTTP requests to internal and external resour...
Jul 16, 2024This CVE describes a server-side request forgery (SSRF) vulnerability in IBM Datacap Navigator versions 9.1.5 through 9.1.9. An authenticated attacker...
Jul 15, 2024This SSRF vulnerability in WhatsUp Gold allows authenticated users to make unauthorized HTTP requests through the HTTP Monitoring functionality. Attac...
May 14, 2024Homarr dashboard versions before 1.54.0 contain an unauthenticated Server-Side Request Forgery (SSRF) vulnerability that allows attackers to force the...
Mar 7, 2026Chamilo LMS versions before 1.11.28 contain an unauthenticated blind Server-Side Request Forgery (SSRF) vulnerability in the OpenId function. This all...
Mar 2, 2026This Server-Side Request Forgery (SSRF) vulnerability in OpenText XM Fax allows attackers to make the vulnerable server send requests to internal syst...
Feb 19, 2026This vulnerability in Homarr dashboard allows unauthenticated attackers to trigger server-side requests to arbitrary URLs via a public tRPC endpoint. ...
Feb 6, 2026This Server-Side Request Forgery (SSRF) vulnerability in the Prince Radio Player WordPress plugin allows attackers to make unauthorized requests from ...
Jan 23, 2026CVE-2026-24117 is a Server-Side Request Forgery (SSRF) vulnerability in Rekor's /api/v1/index/retrieve endpoint that allows attackers to trigger GET r...
Jan 22, 2026The Nu Html Checker (validator.nu) contains a server-side request forgery (SSRF) vulnerability that allows attackers to bypass hostname-based protecti...
Jan 16, 2026CVE-2021-47776 is a server-side request forgery (SSRF) vulnerability in Umbraco CMS that allows attackers to manipulate baseUrl parameters in dashboar...
Jan 15, 2026CVE-2021-47715 is a server-side request forgery vulnerability in Hasura GraphQL Engine that allows attackers to inject malicious remote schema URLs th...
Dec 22, 2025This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Progress MOVEit Transfer that allows attackers to make unauthorized requests ...
Nov 19, 2025ThinkDashboard versions 0.6.7 and below contain a blind SSRF vulnerability in the /api/ping?url= endpoint that allows attackers to make arbitrary HTTP...
Nov 6, 2025This vulnerability allows unauthenticated attackers to perform Blind Server-Side Request Forgery (SSRF) attacks against WordPress sites using the MxCh...
Oct 23, 2025CVE-2025-62612 is a Server-Side Request Forgery (SSRF) vulnerability in FastGPT's workflow file reading node that allows attackers to make unauthorize...
Oct 22, 2025This Server-Side Request Forgery (SSRF) vulnerability in the captcha.eu WordPress plugin allows attackers to make the server send unauthorized request...
Oct 22, 2025CVE-2025-10695 is a Server-Side Request Forgery (SSRF) vulnerability in OpenSupports that allows unauthenticated attackers to make arbitrary network r...
Oct 3, 2025Dify v1.6.0 contains a Server-Side Request Forgery (SSRF) vulnerability in the RemoteFileUploadApi component that allows attackers to make unauthorize...
Sep 30, 2025O'View MapServer developed by PilotGaea Technologies has a Server-Side Request Forgery (SSRF) vulnerability that allows unauthenticated remote attacke...
Sep 15, 2025This SSRF vulnerability in Salesforce Tableau Server allows attackers to make the server send requests to internal resources, potentially accessing se...
Jul 25, 2025Applio voice conversion tool versions 3.2.7 and earlier contain server-side request forgery (SSRF) and arbitrary file write vulnerabilities in model_d...
Mar 19, 2025Applio versions 3.2.7 and earlier contain a server-side request forgery (SSRF) vulnerability in model_download.py that allows attackers to send reques...
Mar 19, 2025The Starter Templates by FancyWP WordPress plugin has a blind SSRF vulnerability that allows unauthenticated attackers to make arbitrary HTTP requests...
Mar 8, 2025This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Zimbra Collaboration's RSS feed parser. It allows attackers to redirect reque...
Feb 3, 2025Imgproxy fails to block the 0.0.0.0 address even when loopback source addresses are restricted, allowing attackers to potentially access services on t...
Jan 27, 2025About Server-Side Request Forgery (SSRF) (CWE-918)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Our database tracks 816 CVEs classified as CWE-918, with 170 rated critical and 311 rated high severity. The average CVSS score for Server-Side Request Forgery (SSRF) vulnerabilities is 7.2.
External reference: View CWE-918 on MITRE CWE →
Monitor Server-Side Request Forgery (SSRF) Vulnerabilities
Get alerted when new Server-Side Request Forgery (SSRF) CVEs affect your infrastructure.
Start Monitoring Free