CWE-918: Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

816
Total CVEs
170
Critical
311
High
7.2
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
121
2025
340
2024
157
2023
60
2022
53

Top Affected Vendors

1 Microsoft 16
2 Apache 16
3 Ibm 9
4 Sap 8
5 Gitlab 7
6 Agpt 5
7 Maccms 5
8 Craftcms 5
9 Langchain 4
10 Progress 4

All Server-Side Request Forgery (SSRF) CVEs (816)

CVE-2026-22358
5.4

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the Electrician - Electrical Service WordPress theme. Attackers can exploit t...

Jan 22, 2026
CVE-2026-20958
5.4

This Server-Side Request Forgery (SSRF) vulnerability in Microsoft Office SharePoint allows authenticated attackers to make the server send requests t...

Jan 13, 2026
CVE-2025-62088
5.4

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the WordPress & WooCommerce Scraper Plugin, Import Data from Any Site. It all...

Dec 31, 2025
CVE-2025-67989
5.4

This Server-Side Request Forgery (SSRF) vulnerability in the LMPixels Kerge WordPress theme allows attackers to make unauthorized requests from the vu...

Dec 16, 2025
CVE-2025-12359
5.4

The Responsive Lightbox & Gallery WordPress plugin has a Server-Side Request Forgery vulnerability that allows authenticated attackers with Author-lev...

Nov 19, 2025
CVE-2025-36085
5.4

IBM Concert versions 1.0.0 through 2.0.0 contain a server-side request forgery (SSRF) vulnerability that allows authenticated attackers to make unauth...

Oct 28, 2025
CVE-2025-60181
5.4

This Server-Side Request Forgery (SSRF) vulnerability in Silencesoft RSS Reader allows attackers to make the vulnerable server send unauthorized reque...

Sep 26, 2025
CVE-2025-60161
5.4

This Server-Side Request Forgery (SSRF) vulnerability in BdThemes ZoloBlocks WordPress plugin allows attackers to make the vulnerable server send unau...

Sep 26, 2025
CVE-2025-10137
5.4

The Snow Monkey WordPress theme contains a Server-Side Request Forgery (SSRF) vulnerability that allows unauthenticated attackers to make arbitrary we...

Sep 26, 2025
CVE-2025-58005
5.4

This Server-Side Request Forgery (SSRF) vulnerability in the DriCub WordPress theme allows attackers to make unauthorized requests from the vulnerable...

Sep 22, 2025
CVE-2025-58641
5.4

This Server-Side Request Forgery (SSRF) vulnerability in the Exit Intent Popup WordPress plugin allows attackers to make unauthorized requests from th...

Sep 3, 2025
CVE-2025-1142
5.4

IBM Edge Application Manager 4.5 contains a server-side request forgery (SSRF) vulnerability that allows authenticated attackers to make unauthorized ...

Aug 20, 2025
CVE-2025-25229
5.4

Omnissa Workspace ONE UEM contains a Server-Side Request Forgery (SSRF) vulnerability that allows authenticated users to make the server send requests...

Aug 11, 2025
CVE-2025-28963
5.4

This Server-Side Request Forgery (SSRF) vulnerability in Md Yeasin Ul Haider URL Shortener allows attackers to make the vulnerable server send unautho...

Jul 4, 2025
CVE-2025-44043
5.4

Keyoti SearchUnit versions before 9.0.0 are vulnerable to Server-Side Request Forgery (SSRF) in two specific endpoints. Attackers can force the server...

Jun 10, 2025
CVE-2025-47548
5.4

This Server-Side Request Forgery (SSRF) vulnerability in the Wbcom Designs Activity Link Preview For BuddyPress WordPress plugin allows attackers to m...

May 7, 2025
CVE-2025-30964
5.4

This SSRF vulnerability in the Photography WordPress theme allows attackers to make the server send unauthorized requests to internal systems. It affe...

Apr 15, 2025
CVE-2025-28096
5.4

OneNav 1.1.0 contains a Server-Side Request Forgery (SSRF) vulnerability in custom headers functionality. This allows attackers to make unauthorized r...

Mar 28, 2025
CVE-2024-13834
5.4

This vulnerability in the Responsive Plus WordPress plugin allows authenticated attackers with contributor-level access or higher to perform Server-Si...

Feb 15, 2025
CVE-2024-56471
5.4

IBM Aspera Shares versions 1.9.0 through 1.10.0 PL6 contain a server-side request forgery (SSRF) vulnerability that allows authenticated attackers to ...

Feb 5, 2025
CVE-2025-22701
5.4

This Server-Side Request Forgery (SSRF) vulnerability in the Traveler Layout Essential For Elementor WordPress plugin allows attackers to make unautho...

Feb 3, 2025
CVE-2024-10705
5.4

The Multiple Page Generator Plugin (MPG) for WordPress versions up to 4.0.5 contains a Server-Side Request Forgery (SSRF) vulnerability in the 'mpg_do...

Jan 26, 2025
CVE-2024-39637
5.4

This Server-Side Request Forgery (SSRF) vulnerability in the Pixelcurve Edubin WordPress theme allows attackers to make unauthorized requests from the...

Aug 1, 2024
CVE-2024-41664
5.4

Canarytokens.org had a blind Server-Side Request Forgery (SSRF) vulnerability in its webhook alert feature that allowed attackers to map internal netw...

Jul 23, 2024
CVE-2023-31456
5.4

This SSRF vulnerability in Fluid Topics allows authenticated users to force the server to make arbitrary HTTP requests to internal and external resour...

Jul 16, 2024
CVE-2024-39739
5.4

This CVE describes a server-side request forgery (SSRF) vulnerability in IBM Datacap Navigator versions 9.1.5 through 9.1.9. An authenticated attacker...

Jul 15, 2024
CVE-2024-4562
5.4

This SSRF vulnerability in WhatsUp Gold allows authenticated users to make unauthorized HTTP requests through the HTTP Monitoring functionality. Attac...

May 14, 2024
CVE-2026-27797
5.3

Homarr dashboard versions before 1.54.0 contain an unauthenticated Server-Side Request Forgery (SSRF) vulnerability that allows attackers to force the...

Mar 7, 2026
CVE-2024-50337
5.3

Chamilo LMS versions before 1.11.28 contain an unauthenticated blind Server-Side Request Forgery (SSRF) vulnerability in the OpenId function. This all...

Mar 2, 2026
CVE-2025-8055
5.3

This Server-Side Request Forgery (SSRF) vulnerability in OpenText XM Fax allows attackers to make the vulnerable server send requests to internal syst...

Feb 19, 2026
CVE-2026-25123
5.3

This vulnerability in Homarr dashboard allows unauthenticated attackers to trigger server-side requests to arbitrary URLs via a public tRPC endpoint. ...

Feb 6, 2026
CVE-2026-24548
5.3

This Server-Side Request Forgery (SSRF) vulnerability in the Prince Radio Player WordPress plugin allows attackers to make unauthorized requests from ...

Jan 23, 2026
CVE-2026-24117
5.3

CVE-2026-24117 is a Server-Side Request Forgery (SSRF) vulnerability in Rekor's /api/v1/index/retrieve endpoint that allows attackers to trigger GET r...

Jan 22, 2026
CVE-2025-15104
5.3

The Nu Html Checker (validator.nu) contains a server-side request forgery (SSRF) vulnerability that allows attackers to bypass hostname-based protecti...

Jan 16, 2026
CVE-2021-47776
5.3

CVE-2021-47776 is a server-side request forgery (SSRF) vulnerability in Umbraco CMS that allows attackers to manipulate baseUrl parameters in dashboar...

Jan 15, 2026
CVE-2021-47715
5.3

CVE-2021-47715 is a server-side request forgery vulnerability in Hasura GraphQL Engine that allows attackers to inject malicious remote schema URLs th...

Dec 22, 2025
CVE-2025-13147
5.3

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Progress MOVEit Transfer that allows attackers to make unauthorized requests ...

Nov 19, 2025
CVE-2025-64327
5.3

ThinkDashboard versions 0.6.7 and below contain a blind SSRF vulnerability in the /api/ping?url= endpoint that allows attackers to make arbitrary HTTP...

Nov 6, 2025
CVE-2025-10705
5.3

This vulnerability allows unauthenticated attackers to perform Blind Server-Side Request Forgery (SSRF) attacks against WordPress sites using the MxCh...

Oct 23, 2025
CVE-2025-62612
5.3

CVE-2025-62612 is a Server-Side Request Forgery (SSRF) vulnerability in FastGPT's workflow file reading node that allows attackers to make unauthorize...

Oct 22, 2025
CVE-2025-49374
5.3

This Server-Side Request Forgery (SSRF) vulnerability in the captcha.eu WordPress plugin allows attackers to make the server send unauthorized request...

Oct 22, 2025
CVE-2025-10695
5.3

CVE-2025-10695 is a Server-Side Request Forgery (SSRF) vulnerability in OpenSupports that allows unauthenticated attackers to make arbitrary network r...

Oct 3, 2025
CVE-2025-56520
5.3

Dify v1.6.0 contains a Server-Side Request Forgery (SSRF) vulnerability in the RemoteFileUploadApi component that allows attackers to make unauthorize...

Sep 30, 2025
CVE-2025-10453
5.3

O'View MapServer developed by PilotGaea Technologies has a Server-Side Request Forgery (SSRF) vulnerability that allows unauthenticated remote attacke...

Sep 15, 2025
CVE-2025-52454
5.3

This SSRF vulnerability in Salesforce Tableau Server allows attackers to make the server send requests to internal resources, potentially accessing se...

Jul 25, 2025
CVE-2025-27774
5.3

Applio voice conversion tool versions 3.2.7 and earlier contain server-side request forgery (SSRF) and arbitrary file write vulnerabilities in model_d...

Mar 19, 2025
CVE-2025-27776
5.3

Applio versions 3.2.7 and earlier contain a server-side request forgery (SSRF) vulnerability in model_download.py that allows attackers to send reques...

Mar 19, 2025
CVE-2024-13924
5.3

The Starter Templates by FancyWP WordPress plugin has a blind SSRF vulnerability that allows unauthenticated attackers to make arbitrary HTTP requests...

Mar 8, 2025
CVE-2025-25065
5.3

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Zimbra Collaboration's RSS feed parser. It allows attackers to redirect reque...

Feb 3, 2025
CVE-2025-24354
5.3

Imgproxy fails to block the 0.0.0.0 address even when loopback source addresses are restricted, allowing attackers to potentially access services on t...

Jan 27, 2025

About Server-Side Request Forgery (SSRF) (CWE-918)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Our database tracks 816 CVEs classified as CWE-918, with 170 rated critical and 311 rated high severity. The average CVSS score for Server-Side Request Forgery (SSRF) vulnerabilities is 7.2.

External reference: View CWE-918 on MITRE CWE →

Monitor Server-Side Request Forgery (SSRF) Vulnerabilities

Get alerted when new Server-Side Request Forgery (SSRF) CVEs affect your infrastructure.

Start Monitoring Free