CWE-918: Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

818
Total CVEs
171
Critical
312
High
7.2
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
121
2025
340
2024
157
2023
60
2022
53

Top Affected Vendors

1 Microsoft 16
2 Apache 16
3 Ibm 9
4 Sap 8
5 Gitlab 8
6 Agpt 5
7 Maccms 5
8 Craftcms 5
9 Langchain 4
10 Progress 4

All Server-Side Request Forgery (SSRF) CVEs (818)

CVE-2025-25065
5.3

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Zimbra Collaboration's RSS feed parser. It allows attackers to redirect reque...

Feb 3, 2025
CVE-2025-24354
5.3

Imgproxy fails to block the 0.0.0.0 address even when loopback source addresses are restricted, allowing attackers to potentially access services on t...

Jan 27, 2025
CVE-2024-6538
5.3

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in OpenShift Console's /api/dev-console/proxy/internet endpoint. Authenticated u...

Nov 25, 2024
CVE-2024-9410
5.3

This vulnerability in Ada.cx's Sentry configuration allows attackers to perform blind server-side request forgery (SSRF) attacks through a data scrapi...

Oct 4, 2024
CVE-2024-33117
5.3

CVE-2024-33117 is a Server-Side Request Forgery (SSRF) vulnerability in crmeb_java v1.3.4 that allows attackers to make the server send unauthorized r...

May 6, 2024
CVE-2024-46413
5.1

CVE-2024-46413 is a Server-Side Request Forgery (SSRF) vulnerability in Rebuild v3.7.7 that allows attackers to make the server send HTTP requests to ...

Aug 25, 2025
CVE-2026-1249
5.0

This SSRF vulnerability in the MP3 Audio Player WordPress plugin allows authenticated attackers with author-level access to make arbitrary web request...

Feb 14, 2026
CVE-2026-26005
5.0

ClipBucket v5's Remote Play feature allows users to create video entries referencing external URLs. Attackers can exploit this by specifying internal ...

Feb 12, 2026
CVE-2025-14793
5.0

The DK PDF WordPress plugin is vulnerable to Server-Side Request Forgery (SSRF) that allows authenticated attackers (author level or higher) to make a...

Jan 16, 2026
CVE-2025-62763
5.0

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Zimbra Collaboration Suite (ZCS) versions before 10.1.12, caused by misconfig...

Oct 21, 2025
CVE-2025-11536
5.0

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to perform blind Server-Side Request Forgery (SSRF) att...

Oct 20, 2025
CVE-2025-9799
5.0

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Langfuse's webhook handler. Attackers can manipulate the promptChangeEventSou...

Sep 1, 2025
CVE-2025-8341
5.0

The Grafana Infinity datasource plugin contains a URL restriction bypass vulnerability that allows attackers to access unauthorized endpoints. This af...

Aug 4, 2025
CVE-2023-35817
5.0

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in DevExpress AsyncDownloader components. Attackers can exploit this to make the...

Apr 28, 2025
CVE-2024-41737
5.0

CVE-2024-41737 is a server-side request forgery (SSRF) vulnerability in SAP CRM ABAP Insights Management that allows authenticated attackers to enumer...

Aug 13, 2024
CVE-2024-37171
5.0

This Server-Side Request Forgery (SSRF) vulnerability in SAP Transportation Management (Collaboration Portal) allows authenticated non-administrative ...

Jul 9, 2024
CVE-2024-39699
5.0

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Directus that allows attackers to bypass DNS resolution protections via HTTP ...

Jul 8, 2024
CVE-2026-25310
4.9

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the Alobaidi Extend Link WordPress plugin. It allows attackers to make the vu...

Feb 19, 2026
CVE-2026-25511
4.9

This vulnerability allows authenticated users in the System Administrator group of Group-Office to perform Server-Side Request Forgery (SSRF) attacks ...

Feb 4, 2026
CVE-2026-24767
4.9

NocoDB versions before 0.301.0 contain a blind SSRF vulnerability in the uploadViaURL functionality. The initial HEAD request for metadata lacks SSRF ...

Jan 28, 2026
CVE-2025-64252
4.9

This Server-Side Request Forgery (SSRF) vulnerability in the ANAC XML Viewer WordPress plugin allows attackers to make the vulnerable server send unau...

Jan 22, 2026
CVE-2025-49335
4.9

This SSRF vulnerability in the WordPress External Media plugin allows attackers to make unauthorized requests from the server to internal or external ...

Jan 7, 2026
CVE-2025-59138
4.9

This Server-Side Request Forgery (SSRF) vulnerability in the Jthemes Genemy WordPress theme allows attackers to make unauthorized requests from the vu...

Dec 31, 2025
CVE-2025-69014
4.9

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the Youzify WordPress plugin. Attackers can exploit this vulnerability to mak...

Dec 30, 2025
CVE-2025-68893
4.9

This SSRF vulnerability in the HETWORKS WordPress Image Shrinker plugin allows attackers to make the server send requests to internal or external syst...

Dec 29, 2025
CVE-2025-27232
4.9

An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver, potentially exposing sensitive ...

Dec 1, 2025
CVE-2025-62988
4.9

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the WordPress Slider Templates plugin. It allows attackers to make the vulner...

Oct 27, 2025
CVE-2025-58977
4.9

This SSRF vulnerability in WP eBay Product Feeds allows attackers to make unauthorized requests from the vulnerable server to internal or external sys...

Sep 9, 2025
CVE-2025-58829
4.9

This SSRF vulnerability in the Ai Auto Tool Content Writing Assistant WordPress plugin allows attackers to make the server send unauthorized requests ...

Sep 5, 2025
CVE-2025-49984
4.9

This SSRF vulnerability in the PowerPress Podcasting WordPress plugin allows attackers to make unauthorized requests from the server to internal or ex...

Jun 20, 2025
CVE-2025-47464
4.9

This Server-Side Request Forgery (SSRF) vulnerability in the Solace Extra WordPress plugin allows attackers to make the vulnerable server send unautho...

May 7, 2025
CVE-2025-46443
4.9

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the Adam Pery Animate WordPress plugin. It allows attackers to make the vulne...

Apr 24, 2025
CVE-2025-32691
4.9

This Server-Side Request Forgery (SSRF) vulnerability in the PowerPress Podcasting WordPress plugin allows attackers to make the vulnerable server sen...

Apr 9, 2025
CVE-2025-32487
4.9

This Server-Side Request Forgery (SSRF) vulnerability in the Waymark WordPress plugin allows attackers to make unauthorized requests from the server t...

Apr 9, 2025
CVE-2025-31076
4.9

This Server-Side Request Forgery (SSRF) vulnerability in WP Compress for MainWP allows attackers to make the vulnerable server send HTTP requests to i...

Mar 28, 2025
CVE-2025-22672
4.9

This Server-Side Request Forgery (SSRF) vulnerability in the SuitePlugins Video & Photo Gallery for Ultimate Member WordPress plugin allows attackers ...

Mar 27, 2025
CVE-2024-48234
4.9

This SSRF vulnerability in mipjz 5.0.5 allows attackers to make the server send HTTP requests to internal systems by manipulating the postAddress para...

Oct 25, 2024
CVE-2024-48232
4.9

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in mipjz 5.0.5 where the mipPost method in ApiAdminTool.php fails to validate th...

Oct 25, 2024
CVE-2024-45119
4.9

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Adobe Commerce that allows authenticated administrators to force the applicat...

Oct 10, 2024
CVE-2024-38758
4.9

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the WappPress WordPress plugin. Attackers can exploit this to make the vulner...

Jul 20, 2024
CVE-2026-1356
4.8

This Server-Side Request Forgery (SSRF) vulnerability in the Converter for Media WordPress plugin allows unauthenticated attackers to make arbitrary w...

Feb 12, 2026
CVE-2025-63010
4.8

This Server-Side Request Forgery (SSRF) vulnerability in ThemesInflow Hercules Core WordPress plugin allows attackers to make unauthorized requests fr...

Dec 9, 2025
CVE-2024-13697
4.8

This vulnerability allows unauthenticated attackers to perform Server-Side Request Forgery (SSRF) attacks via the 'nice_links' feature in the Better M...

Mar 1, 2025
CVE-2024-4219
4.8

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in BeyondInsight HTTP-based connectors that allows attackers to make arbitrary H...

Jun 4, 2024
CVE-2026-1884
4.7

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in ZenTao's Webhook Module. Attackers can exploit the fetchHook function to make...

Feb 4, 2026
CVE-2026-0649
4.7

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in InvoiceNinja's migration import functionality. Attackers can manipulate the c...

Jan 7, 2026
CVE-2025-15414
4.7

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in go-sonic's Theme Fetching API. Attackers can manipulate the 'uri' parameter i...

Jan 1, 2026
CVE-2025-14116
4.7

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in xerrors Yuxi-Know software up to version 0.4.0. Attackers can manipulate the ...

Dec 5, 2025
CVE-2025-14008
4.7

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in dayrui XunRuiCMS up to version 4.7.1. Attackers can exploit this by manipulat...

Dec 4, 2025
CVE-2025-14004
4.7

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in dayrui XunRuiCMS up to version 4.7.1. The flaw allows attackers to make unaut...

Dec 4, 2025

About Server-Side Request Forgery (SSRF) (CWE-918)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Our database tracks 818 CVEs classified as CWE-918, with 171 rated critical and 312 rated high severity. The average CVSS score for Server-Side Request Forgery (SSRF) vulnerabilities is 7.2.

External reference: View CWE-918 on MITRE CWE →

Monitor Server-Side Request Forgery (SSRF) Vulnerabilities

Get alerted when new Server-Side Request Forgery (SSRF) CVEs affect your infrastructure.

Start Monitoring Free