CWE-918: Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Yearly Trend
Top Affected Vendors
All Server-Side Request Forgery (SSRF) CVEs (830)
This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the WappPress WordPress plugin. Attackers can exploit this to make the vulner...
Jul 20, 2024This Server-Side Request Forgery (SSRF) vulnerability in the Converter for Media WordPress plugin allows unauthenticated attackers to make arbitrary w...
Feb 12, 2026This Server-Side Request Forgery (SSRF) vulnerability in ThemesInflow Hercules Core WordPress plugin allows attackers to make unauthorized requests fr...
Dec 9, 2025This vulnerability allows unauthenticated attackers to perform Server-Side Request Forgery (SSRF) attacks via the 'nice_links' feature in the Better M...
Mar 1, 2025This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in BeyondInsight HTTP-based connectors that allows attackers to make arbitrary H...
Jun 4, 2024This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in ContiNew Admin's storage management module. Attackers can exploit the URI.cre...
Mar 8, 2026This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in ZenTao's Webhook Module. Attackers can exploit the fetchHook function to make...
Feb 4, 2026This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in InvoiceNinja's migration import functionality. Attackers can manipulate the c...
Jan 7, 2026This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in go-sonic's Theme Fetching API. Attackers can manipulate the 'uri' parameter i...
Jan 1, 2026This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in xerrors Yuxi-Know software up to version 0.4.0. Attackers can manipulate the ...
Dec 5, 2025This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in dayrui XunRuiCMS up to version 4.7.1. Attackers can exploit this by manipulat...
Dec 4, 2025This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in dayrui XunRuiCMS up to version 4.7.1. The flaw allows attackers to make unaut...
Dec 4, 2025This vulnerability allows remote attackers to perform server-side request forgery (SSRF) attacks against samanhappy MCPHub installations up to version...
Oct 5, 2025This CVE describes a blind Server-Side Request Forgery (SSRF) vulnerability in TCL 65C655 Smart TVs that allows unauthenticated attackers to make the ...
Oct 3, 2025This vulnerability allows remote attackers to perform server-side request forgery (SSRF) attacks against SeriaWei ZKEACMS installations up to version ...
Sep 21, 2025This vulnerability in Magicblack MacCMS 2025.1000.4050 allows remote attackers to perform server-side request forgery (SSRF) by manipulating the 'cjur...
Sep 14, 2025This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in kodbox 1.61's download handler. Attackers can manipulate the 'url' parameter ...
Aug 25, 2025This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in HuangDou UTCMS 9 that allows attackers to manipulate the UPDATEURL parameter ...
Aug 25, 2025This critical Server-Side Request Forgery (SSRF) vulnerability in Vvveb's Drag-and-Drop Editor allows attackers to make unauthorized requests from the...
Aug 4, 2025This Server-Side Request Forgery (SSRF) vulnerability in WonderCMS v3.4.3 allows attackers to force the application to make arbitrary HTTP requests to...
Jul 30, 2024This SSRF vulnerability in Seriously Simple Podcasting WordPress plugin allows attackers to make unauthorized requests from the server to internal or ...
Jan 22, 2026This CVE describes a server-side request forgery (SSRF) vulnerability in IBM InfoSphere Information Server versions 11.7.0.0 through 11.7.1.6. An auth...
Dec 8, 2025This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the Emplibot WordPress plugin that allows authenticated administrators to mak...
Dec 13, 2025This SSRF vulnerability in Icegram Express Pro WordPress plugin allows attackers to make unauthorized requests from the vulnerable server to internal ...
Oct 22, 2025This SSRF vulnerability in the MakeStories WordPress plugin allows attackers to make unauthorized requests from the server to internal or external sys...
Sep 22, 2025This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the Skimlinks Affiliate Marketing Tool WordPress plugin, allowing attackers t...
Sep 22, 2025This Server-Side Request Forgery (SSRF) vulnerability in the Beaf WordPress plugin allows attackers to make the server send unauthorized requests to i...
Sep 22, 2025This Server-Side Request Forgery (SSRF) vulnerability in the SEO Backlink Monitor WordPress plugin allows attackers to make unauthorized requests from...
Sep 22, 2025This SSRF vulnerability in WP Bannerize Pro allows attackers to make the WordPress server send unauthorized requests to internal or external systems. ...
Sep 3, 2025This Server-Side Request Forgery (SSRF) vulnerability in the Solace Extra WordPress plugin allows attackers to make unauthorized requests from the vul...
Aug 27, 2025This vulnerability in Cursor code editor versions below 1.3 allows attackers to exfiltrate sensitive information via Mermaid diagram image rendering. ...
Aug 1, 2025This SSRF vulnerability in ThimPress WP Pipes WordPress plugin allows attackers to make unauthorized requests from the server to internal or external ...
May 7, 2025This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Mobile Security Framework (MobSF) where the mitigation for a previous SSRF vu...
Mar 31, 2025This Server-Side Request Forgery (SSRF) vulnerability in XpeedStudio's Metform WordPress plugin allows attackers to make the vulnerable server send HT...
Mar 27, 2025A Server-Side Request Forgery (SSRF) vulnerability in Kiboko Labs Chained Quiz WordPress plugin allows attackers to make unauthorized requests from th...
Jan 24, 2025This Server-Side Request Forgery (SSRF) vulnerability in the WordPress Comment Edit Core plugin allows attackers to make the vulnerable server send un...
Jan 24, 2025This Server-Side Request Forgery (SSRF) vulnerability in the BlossomThemes Email Newsletter WordPress plugin allows attackers to make the server send ...
Jun 26, 2024This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the Ninja Tables WordPress plugin by WPManageNinja LLC. It allows attackers t...
Jun 3, 2024This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the Church Admin WordPress plugin. It allows attackers to make the vulnerable...
Jun 3, 2024This SSRF vulnerability in a-blog CMS allows authenticated administrators to read arbitrary files on the server and access internal network resources....
May 22, 2024This vulnerability allows authenticated attackers in SPIP's private area to perform blind Server-Side Request Forgery (SSRF) when editing syndicated s...
Feb 19, 2026This vulnerability allows authenticated WordPress users with Contributor-level permissions or higher to perform Server-Side Request Forgery attacks ag...
Feb 18, 2026Tiny File Manager versions up to 2.6 contain a server-side request forgery (SSRF) vulnerability in the URL upload feature. Attackers can bypass URL va...
Feb 3, 2026The Featured Image from URL (FIFU) WordPress plugin up to version 5.3.1 has a Server-Side Request Forgery vulnerability in its Elementor widget integr...
Jan 10, 2026This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Hemmelig's webhook URL validation that allows authenticated users to bypass I...
Dec 29, 2025The Prime Slider plugin for WordPress has a Server-Side Request Forgery (SSRF) vulnerability that allows authenticated users with subscriber-level acc...
Dec 18, 2025This SSRF vulnerability in LinkAce allows authenticated attackers to make the application server send HTTP requests to internal network resources, ena...
Nov 4, 2025This vulnerability in SAP BI Platform allows attackers to modify the LogonToken IP address for OpenDoc, potentially redirecting ping requests to diffe...
Sep 23, 2025The B Slider WordPress plugin versions ≤2.0.0 contain a Server-Side Request Forgery (SSRF) vulnerability in the fs_api_request function. Authenticat...
Aug 15, 2025This vulnerability allows attackers to perform server-side request forgery (SSRF) attacks against NukeViet CMS installations. Attackers can manipulate...
Aug 9, 2025About Server-Side Request Forgery (SSRF) (CWE-918)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Our database tracks 830 CVEs classified as CWE-918, with 178 rated critical and 315 rated high severity. The average CVSS score for Server-Side Request Forgery (SSRF) vulnerabilities is 7.2.
External reference: View CWE-918 on MITRE CWE →
Monitor Server-Side Request Forgery (SSRF) Vulnerabilities
Get alerted when new Server-Side Request Forgery (SSRF) CVEs affect your infrastructure.
Start Monitoring Free