CWE-918: Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Yearly Trend
Top Affected Vendors
All Server-Side Request Forgery (SSRF) CVEs (803)
This CVE-2025-59088 vulnerability in kdcproxy allows attackers to perform server-side request forgery (SSRF) by sending requests for realms without de...
Nov 12, 2025The Ditty WordPress plugin before version 3.1.58 has an authentication bypass vulnerability in its displayItems endpoint. This allows unauthenticated ...
Sep 8, 2025This Server-Side Request Forgery (SSRF) vulnerability in Pik Online allows attackers to make unauthorized requests from the vulnerable server to inter...
Aug 20, 2025CVE-2025-55161 is a Server-Side Request Forgery (SSRF) vulnerability in Stirling-PDF's Markdown-to-PDF conversion endpoint. Attackers can bypass secur...
Aug 11, 2025CVE-2025-55150 is a Server-Side Request Forgery (SSRF) vulnerability in Stirling-PDF's HTML-to-PDF conversion endpoint. Attackers can bypass security ...
Aug 11, 2025This CVE describes a pre-authentication blind Server-Side Request Forgery (SSRF) vulnerability in Liferay Portal and DXP. Attackers can force vulnerab...
Aug 9, 2025This Server-Side Request Forgery (SSRF) vulnerability in Eveo URVE Web Manager allows attackers to make the application server send requests to intern...
Jul 21, 2025Octo-STS versions before v0.5.3 are vulnerable to unauthenticated server-side request forgery (SSRF) via malicious OpenID Connect tokens. Attackers ca...
Jun 26, 2025This CVE describes a server-side request forgery (SSRF) vulnerability in a-blog CMS that allows remote unauthenticated attackers to make the server se...
May 19, 2025This is a Server-Side Request Forgery (SSRF) vulnerability in Hitachi Vantara Pentaho Business Analytics Server where the server doesn't validate the ...
Feb 19, 2025Label Studio versions before 1.16.0 contain a Server-Side Request Forgery (SSRF) vulnerability in the S3 storage integration feature. Attackers can ex...
Feb 14, 2025This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Nuxt Icon's API endpoint. Attackers can manipulate the proxied request path t...
Aug 5, 2024This Server-Side Request Forgery (SSRF) vulnerability in Rocket.Chat's Twilio webhook endpoint allows attackers to make unauthorized requests to inter...
Aug 5, 2024This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Strapi v4.24.4 that allows attackers to make unauthorized requests from the s...
Jun 20, 2024A Server-Side Request Forgery (SSRF) vulnerability in gradio-app/gradio version 4.21.0 allows attackers to make unauthorized HTTP requests from the vu...
Jun 6, 2024This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in 71cms v1.0.0 that allows remote unauthenticated attackers to make the server ...
Apr 2, 2024CVE-2023-46236 is a server-side request forgery (SSRF) vulnerability in FOG Project that allows unauthenticated attackers to make arbitrary GET reques...
Oct 31, 2023This vulnerability in GeoServer's OGC Web Processing Service (WPS) allows Server-Side Request Forgery (SSRF), enabling attackers to make unauthorized ...
Oct 25, 2023This CVE allows attackers to perform Server-Side Request Forgery (SSRF) attacks against GeoServer instances with dynamic styling enabled but without U...
Oct 25, 2023This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Plane project management software. Attackers with workspace ADMIN privileges ...
Mar 6, 2026This Server-Side Request Forgery (SSRF) vulnerability in SillyTavern allows authenticated users to make arbitrary HTTP requests from the server and re...
Feb 19, 2026Open WebUI versions before 0.6.37 contain a Server-Side Request Forgery (SSRF) vulnerability that allows any authenticated user to make the server sen...
Dec 4, 2025This CVE describes a Server-Side Request Forgery (SSRF) bypass vulnerability in New API (an LLM gateway and AI asset management system). Attackers can...
Nov 25, 2025An authenticated Server-Side Request Forgery (SSRF) vulnerability in New API versions before 0.9.0.5 allows authenticated users to make the server sen...
Oct 9, 2025This vulnerability allows authenticated users in GitLab to inject crafted sequences that bypass proxy environment restrictions, enabling unintended in...
Sep 12, 2025The Modern Events Calendar WordPress plugin contains a Server-Side Request Forgery (SSRF) vulnerability that allows authenticated attackers with Subsc...
Aug 7, 2024An authenticated attacker can bypass SSRF protection in Microsoft Copilot Studio to make unauthorized requests to internal network resources, potentia...
Aug 6, 2024This vulnerability in Pi-hole allows authenticated users to make internal requests to the server via the gravity_DownloadBlocklistFromUrl() function, ...
Jul 5, 2024The ElementsKit PRO WordPress plugin versions up to 3.6.2 contain a Server-Side Request Forgery (SSRF) vulnerability in the 'render_raw' function. Thi...
Jun 14, 2024The MemberPress WordPress plugin contains a blind server-side request forgery (SSRF) vulnerability that allows authenticated attackers with Contributo...
May 22, 2024This vulnerability in the Kadence Blocks WordPress plugin allows authenticated attackers with contributor-level access or higher to perform Server-Sid...
Apr 9, 2024Pega Platform versions 8.2.1 through 23.1.0 contain a server-side request forgery (SSRF) vulnerability in the PDF generation functionality. This allow...
Jan 31, 2024OpenClaw versions before 2026.2.14 contain a server-side request forgery vulnerability in the Tlon Urbit extension. Attackers who can influence the co...
Mar 5, 2026This SSRF vulnerability in vanna-ai/vanna with DuckDB allows attackers to execute crafted SQL queries that abuse DuckDB's file reading functions to ma...
Mar 20, 2025This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in PostHog's database_schema method that allows authenticated attackers to make ...
Nov 22, 2024The Mapplic and Mapplic Lite WordPress plugins contain a Server-Side Request Forgery (SSRF) vulnerability that allows attackers to make requests from ...
Oct 16, 2024This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in cBioPortal's proxy endpoint. Unauthenticated attackers can exploit publicly e...
Jul 23, 2024CVE-2020-24139 is a server-side request forgery (SSRF) vulnerability in Wcms 0.3.2 that allows attackers to make arbitrary HTTP requests from the vuln...
Apr 7, 2021CVE-2025-68696 is a Server-Side Request Forgery (SSRF) vulnerability in the httparty Ruby gem that allows attackers to make unauthorized requests to i...
Dec 23, 2025The ssrfcheck package versions before 1.2.0 are vulnerable to Server-Side Request Forgery (SSRF) due to an incomplete IP address denylist that fails t...
Jul 28, 2025The private-ip npm package is vulnerable to Server-Side Request Forgery (SSRF) because it fails to properly validate multicast IP addresses (224.0.0.0...
Jul 23, 2025This SSRF vulnerability in spatie/browsershot allows attackers to make the server request internal network resources, potentially exposing localhost d...
Apr 4, 2025This SSRF vulnerability in nossrf versions before 1.0.4 allows attackers to bypass protection mechanisms by providing hostnames that resolve to local ...
Mar 23, 2025This vulnerability allows Server-Side Request Forgery (SSRF) attacks against GitLab Enterprise Edition instances with Product Analytics Dashboard enab...
Oct 10, 2024This CVE describes a Server-Side Request Forgery (SSRF) vulnerability affecting multiple WordPress plugins and themes. It allows attackers to make una...
Jan 19, 2024This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the Fides privacy engineering platform. Attackers can upload malicious YAML f...
Oct 25, 2023CVE-2023-41054 is a Server-Side Request Forgery (SSRF) vulnerability in LibreY's image_proxy.php that allows attackers to use the server as a proxy to...
Sep 4, 2023This Server-Side Request Forgery (SSRF) vulnerability in the Scout application allows attackers to make the server send arbitrary HTTP requests to int...
May 5, 2022This SSRF vulnerability in the Shibboleth Identity Provider OIDC OP plugin allows attackers to make arbitrary HTTP requests to third-party services by...
Feb 4, 2022AutoGPT versions prior to beta-v0.4.2 contain a server-side request forgery (SSRF) vulnerability in the 'Send Web Request' component that fails to fil...
Mar 10, 2025About Server-Side Request Forgery (SSRF) (CWE-918)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Our database tracks 803 CVEs classified as CWE-918, with 165 rated critical and 305 rated high severity. The average CVSS score for Server-Side Request Forgery (SSRF) vulnerabilities is 7.2.
External reference: View CWE-918 on MITRE CWE →
Monitor Server-Side Request Forgery (SSRF) Vulnerabilities
Get alerted when new Server-Side Request Forgery (SSRF) CVEs affect your infrastructure.
Start Monitoring Free