CWE-918: Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Yearly Trend
Top Affected Vendors
All Server-Side Request Forgery (SSRF) CVEs (794)
This Server-Side Request Forgery (SSRF) vulnerability in Infoline Project Management System allows attackers to make unauthorized requests from the se...
Mar 30, 2023CVE-2022-46973 is a Server-Side Request Forgery (SSRF) vulnerability in Report v0.9.8.6 that allows attackers to make unauthorized requests from the v...
Mar 3, 2023CVE-2022-37938 is an unauthenticated server-side request forgery (SSRF) vulnerability in HPE Serviceguard Manager that allows attackers to make arbitr...
Mar 1, 2023This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the parse-url npm package versions prior to 7.0.0. Attackers can exploit this...
Jun 27, 2022flatCore-CMS version 2.0.8 contains dangerous function calls that allow server-side request forgery (SSRF) attacks. This vulnerability enables attacke...
Jun 15, 2022This SSRF vulnerability in HPE OneView allows attackers to make unauthorized requests from the vulnerable server to internal systems. Attackers could ...
May 17, 2022This vulnerability in the Fusion Builder WordPress plugin (used by Avada theme) allows attackers to make arbitrary HTTP requests from the vulnerable s...
May 16, 2022This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Northern.tech's Mender Enterprise iot-manager microservice. It allows attacke...
Apr 28, 2022CVE-2022-27311 is a Server-Side Request Forgery (SSRF) vulnerability in Gibbon v3.4.4 and earlier that allows attackers to make unauthorized requests ...
Apr 25, 2022Jizhicms v1.9.5 contains a Server-Side Request Forgery (SSRF) vulnerability in the /admin.php/Plugins/update.html endpoint. This allows attackers to m...
Apr 25, 2022This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Calibre-Web, an open-source web application for managing eBook collections. A...
Mar 7, 2022CVE-2022-24568 is a Server-Side Request Forgery (SSRF) vulnerability in Novel-plus v3.6.0 that allows attackers to make arbitrary HTTP requests from t...
Feb 10, 2022This Server Side Request Forgery (SSRF) vulnerability in PrinterLogic Web Stack allows attackers to use user-controlled input to craft URLs, potential...
Feb 2, 2022This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in calibre-web versions prior to 0.6.16. Attackers can exploit this to make the ...
Jan 30, 2022CVE-2022-0086 is a Server-Side Request Forgery (SSRF) vulnerability in the Uppy file uploader library. It allows attackers to make unauthorized reques...
Jan 4, 2022CVE-2021-44659 is a Server-Side Request Forgery (SSRF) vulnerability in GoCD server version 21.3.0 that allows authenticated administrators to abuse p...
Dec 22, 2021CVE-2021-40091 is a Server-Side Request Forgery (SSRF) vulnerability in SquaredUp for SCOM that allows attackers to make unauthorized requests from th...
Dec 6, 2021CVE-2021-22049 is a Server-Side Request Forgery (SSRF) vulnerability in the vSAN Web Client plug-in for vSphere Web Client (FLEX/Flash). It allows att...
Nov 24, 2021CVE-2021-39497 is a Server-Side Request Forgery (SSRF) vulnerability in eyoucms 1.5.4 that allows attackers to inject URLs via the saveRemote() functi...
Sep 7, 2021Nagios XI Docker Wizard versions before 1.1.3 contain a Server-Side Request Forgery (SSRF) vulnerability in table_population.php due to improper input...
Aug 13, 2021This vulnerability allows unauthenticated attackers to make the web server fetch and display content from any URI via exposed proxy functionality in a...
Aug 2, 2021This is a server-side request forgery (SSRF) vulnerability in the Video Downloader for TikTok WordPress plugin version 1.3. It allows attackers to mak...
Jul 7, 2021This Server-Side Request Forgery (SSRF) vulnerability in Zoho ManageEngine ServiceDesk Plus MSP allows attackers to make unauthorized requests from th...
Jun 29, 2021CVE-2020-15377 is a Server-Side Request Forgery (SSRF) vulnerability in Brocade SANnav Webtools that allows unauthenticated attackers to make requests...
Jun 9, 2021CVE-2021-21985 is a critical remote code execution vulnerability in VMware vSphere Client's Virtual SAN Health Check plugin. Attackers with network ac...
May 26, 2021CVE-2017-17674 is a remote/local file inclusion vulnerability in BMC Remedy Mid Tier that allows attackers to read arbitrary files and make unauthoriz...
May 19, 2021This CVE describes a critical Server-Side Request Forgery (SSRF) vulnerability in Aruba ClearPass Policy Manager that can lead to remote code executio...
Apr 29, 2021This SSRF vulnerability in WonderCMS 3.1.3 allows remote attackers to execute arbitrary code by exploiting the theme/plugin installer functionality. A...
Apr 20, 2021CVE-2021-27905 is a Server-Side Request Forgery (SSRF) vulnerability in Apache Solr's ReplicationHandler that allows attackers to make arbitrary HTTP ...
Apr 13, 2021CVE-2021-22986 is an unauthenticated remote command execution vulnerability in the iControl REST interface of F5 BIG-IP and BIG-IQ devices. Attackers ...
Mar 31, 2021This SSRF vulnerability in gopeak masterlab 2.1.5 allows attackers to make arbitrary HTTP requests from the vulnerable server via the 'source' paramet...
Feb 25, 2021CVE-2021-27670 is a Server-Side Request Forgery (SSRF) vulnerability in Appspace 6.2.4 that allows attackers to make unauthorized requests from the vu...
Feb 25, 2021This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Accellion File Transfer Appliance (FTA) versions 9_12_411 and earlier. Attack...
Feb 16, 2021This Server-Side Request Forgery (SSRF) vulnerability in Quest Policy Authority's Web Compliance Manager allows attackers to scan internal network por...
Jan 11, 2021CVE-2020-35712 is a Server-Side Request Forgery (SSRF) vulnerability in Esri ArcGIS Server that allows attackers to make unauthorized requests from th...
Dec 26, 2020CVE-2020-28360 is a Server-Side Request Forgery (SSRF) vulnerability in the private-ip npm package versions 1.0.5 and below. The insufficient regular ...
Nov 23, 2020This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in CRMEB 3.0's downloadimage interface that allows attackers to download arbitra...
Oct 23, 2020This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in libtaxii and OpenTAXII that allows attackers to make arbitrary HTTP requests ...
Oct 17, 2020This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Emby Server that allows attackers to make unauthorized requests from the serv...
Oct 10, 2020This vulnerability in Zimbra Collaboration Suite allows Server-Side Request Forgery (SSRF) when the WebEx zimlet is installed and JSP functionality is...
Feb 18, 2020This SSRF vulnerability in Typebot allows authenticated users to make arbitrary HTTP requests from the server, including accessing AWS Instance Metada...
Nov 13, 2025This SSRF vulnerability in Illia Cloud illia-Builder allows authenticated users to make arbitrary requests to internal services via the API. Attackers...
Oct 17, 2025A Server-Side Request Forgery (SSRF) vulnerability in Logpoint versions before 7.4.0 allows attackers with low-level access to make unauthorized reque...
May 7, 2024This vulnerability in OpenComputers Minecraft mod allows players to access cloud metadata services and local network resources through improperly filt...
Jul 7, 2023Ghostfolio versions before 2.245.0 contain a server-side request forgery (SSRF) vulnerability in the manual asset import feature. Attackers can exploi...
Mar 6, 2026CVE-2025-67494 is an unauthenticated server-side request forgery (SSRF) vulnerability in ZITADEL identity infrastructure. Attackers can force the ZITA...
Dec 9, 2025This SSRF vulnerability in LLaVA's Controller API Server allows attackers to make the server send unauthorized requests to internal or external system...
Mar 20, 2025This SSRF vulnerability in FastChat's Controller API Server allows attackers to make the server send unauthorized requests to internal or external sys...
Dec 30, 2024This CVE describes a server-side request forgery (SSRF) vulnerability in MindsDB that allows attackers to bypass SSRF protection using DNS rebinding t...
Sep 5, 2024This vulnerability in MESbook allows unauthenticated attackers to make server-side requests to internal systems via vulnerable API endpoints. Attacker...
Jul 1, 2024About Server-Side Request Forgery (SSRF) (CWE-918)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Our database tracks 794 CVEs classified as CWE-918, with 163 rated critical and 299 rated high severity. The average CVSS score for Server-Side Request Forgery (SSRF) vulnerabilities is 7.2.
External reference: View CWE-918 on MITRE CWE →
Monitor Server-Side Request Forgery (SSRF) Vulnerabilities
Get alerted when new Server-Side Request Forgery (SSRF) CVEs affect your infrastructure.
Start Monitoring Free