CWE-918: Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

803
Total CVEs
165
Critical
305
High
7.2
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
118
2025
340
2024
157
2023
60
2022
53

Top Affected Vendors

1 Microsoft 16
2 Apache 16
3 Ibm 9
4 Gitlab 7
5 Sap 6
6 Craftcms 5
7 Agpt 5
8 Maccms 5
9 Langchain 4
10 Progress 4

All Server-Side Request Forgery (SSRF) CVEs (803)

CVE-2025-59088
8.6

This CVE-2025-59088 vulnerability in kdcproxy allows attackers to perform server-side request forgery (SSRF) by sending requests for realms without de...

Nov 12, 2025
CVE-2025-8085
EPSS 16.3% 8.6

The Ditty WordPress plugin before version 3.1.58 has an authentication bypass vulnerability in its displayItems endpoint. This allows unauthenticated ...

Sep 8, 2025
CVE-2025-5260
8.6

This Server-Side Request Forgery (SSRF) vulnerability in Pik Online allows attackers to make unauthorized requests from the vulnerable server to inter...

Aug 20, 2025
CVE-2025-55161
8.6

CVE-2025-55161 is a Server-Side Request Forgery (SSRF) vulnerability in Stirling-PDF's Markdown-to-PDF conversion endpoint. Attackers can bypass secur...

Aug 11, 2025
CVE-2025-55150
8.6

CVE-2025-55150 is a Server-Side Request Forgery (SSRF) vulnerability in Stirling-PDF's HTML-to-PDF conversion endpoint. Attackers can bypass security ...

Aug 11, 2025
CVE-2025-4581
8.6

This CVE describes a pre-authentication blind Server-Side Request Forgery (SSRF) vulnerability in Liferay Portal and DXP. Attackers can force vulnerab...

Aug 9, 2025
CVE-2025-36845
8.6

This Server-Side Request Forgery (SSRF) vulnerability in Eveo URVE Web Manager allows attackers to make the application server send requests to intern...

Jul 21, 2025
CVE-2025-52477
8.6

Octo-STS versions before v0.5.3 are vulnerable to unauthenticated server-side request forgery (SSRF) via malicious OpenID Connect tokens. Attackers ca...

Jun 26, 2025
CVE-2025-36560
8.6

This CVE describes a server-side request forgery (SSRF) vulnerability in a-blog CMS that allows remote unauthenticated attackers to make the server se...

May 19, 2025
CVE-2024-37359
8.6

This is a Server-Side Request Forgery (SSRF) vulnerability in Hitachi Vantara Pentaho Business Analytics Server where the server doesn't validate the ...

Feb 19, 2025
CVE-2025-25297
8.6

Label Studio versions before 1.16.0 contain a Server-Side Request Forgery (SSRF) vulnerability in the S3 storage integration feature. Attackers can ex...

Feb 14, 2025
CVE-2024-42352
8.6

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Nuxt Icon's API endpoint. Attackers can manipulate the proxied request path t...

Aug 5, 2024
CVE-2024-39713
8.6

This Server-Side Request Forgery (SSRF) vulnerability in Rocket.Chat's Twilio webhook endpoint allows attackers to make unauthorized requests to inter...

Aug 5, 2024
CVE-2024-37818
8.6

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Strapi v4.24.4 that allows attackers to make unauthorized requests from the s...

Jun 20, 2024
CVE-2024-4325
8.6

A Server-Side Request Forgery (SSRF) vulnerability in gradio-app/gradio version 4.21.0 allows attackers to make unauthorized HTTP requests from the vu...

Jun 6, 2024
CVE-2024-25187
8.6

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in 71cms v1.0.0 that allows remote unauthenticated attackers to make the server ...

Apr 2, 2024
CVE-2023-46236
8.6

CVE-2023-46236 is a server-side request forgery (SSRF) vulnerability in FOG Project that allows unauthenticated attackers to make arbitrary GET reques...

Oct 31, 2023
CVE-2023-43795
8.6

This vulnerability in GeoServer's OGC Web Processing Service (WPS) allows Server-Side Request Forgery (SSRF), enabling attackers to make unauthorized ...

Oct 25, 2023
CVE-2023-41339
8.6

This CVE allows attackers to perform Server-Side Request Forgery (SSRF) attacks against GeoServer instances with dynamic styling enabled but without U...

Oct 25, 2023
CVE-2026-30242
8.5

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Plane project management software. Attackers with workspace ADMIN privileges ...

Mar 6, 2026
CVE-2026-26286
8.5

This Server-Side Request Forgery (SSRF) vulnerability in SillyTavern allows authenticated users to make arbitrary HTTP requests from the server and re...

Feb 19, 2026
CVE-2025-65958
8.5

Open WebUI versions before 0.6.37 contain a Server-Side Request Forgery (SSRF) vulnerability that allows any authenticated user to make the server sen...

Dec 4, 2025
CVE-2025-62155
8.5

This CVE describes a Server-Side Request Forgery (SSRF) bypass vulnerability in New API (an LLM gateway and AI asset management system). Attackers can...

Nov 25, 2025
CVE-2025-59146
8.5

An authenticated Server-Side Request Forgery (SSRF) vulnerability in New API versions before 0.9.0.5 allows authenticated users to make the server sen...

Oct 9, 2025
CVE-2025-6454
8.5

This vulnerability allows authenticated users in GitLab to inject crafted sequences that bypass proxy environment restrictions, enabling unintended in...

Sep 12, 2025
CVE-2024-6522
8.5

The Modern Events Calendar WordPress plugin contains a Server-Side Request Forgery (SSRF) vulnerability that allows authenticated attackers with Subsc...

Aug 7, 2024
CVE-2024-38206
8.5

An authenticated attacker can bypass SSRF protection in Microsoft Copilot Studio to make unauthorized requests to internal network resources, potentia...

Aug 6, 2024
CVE-2024-34361
8.5

This vulnerability in Pi-hole allows authenticated users to make internal requests to the server via the gravity_DownloadBlocklistFromUrl() function, ...

Jul 5, 2024
CVE-2024-4404
8.5

The ElementsKit PRO WordPress plugin versions up to 3.6.2 contain a Server-Side Request Forgery (SSRF) vulnerability in the 'render_raw' function. Thi...

Jun 14, 2024
CVE-2024-5031
8.5

The MemberPress WordPress plugin contains a blind server-side request forgery (SSRF) vulnerability that allows authenticated attackers with Contributo...

May 22, 2024
CVE-2023-6964
8.5

This vulnerability in the Kadence Blocks WordPress plugin allows authenticated attackers with contributor-level access or higher to perform Server-Sid...

Apr 9, 2024
CVE-2023-50165
8.5

Pega Platform versions 8.2.1 through 23.1.0 contain a server-side request forgery (SSRF) vulnerability in the PDF generation functionality. This allow...

Jan 31, 2024
CVE-2026-28476
8.3

OpenClaw versions before 2026.2.14 contain a server-side request forgery vulnerability in the Tlon Urbit extension. Attackers who can influence the co...

Mar 5, 2026
CVE-2024-8099
8.3

This SSRF vulnerability in vanna-ai/vanna with DuckDB allows attackers to execute crafted SQL queries that abuse DuckDB's file reading functions to ma...

Mar 20, 2025
CVE-2024-9710
8.3

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in PostHog's database_schema method that allows authenticated attackers to make ...

Nov 22, 2024
CVE-2012-10018
8.3

The Mapplic and Mapplic Lite WordPress plugins contain a Server-Side Request Forgery (SSRF) vulnerability that allows attackers to make requests from ...

Oct 16, 2024
CVE-2024-41668
8.3

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in cBioPortal's proxy endpoint. Unauthenticated attackers can exploit publicly e...

Jul 23, 2024
CVE-2020-24139
8.3

CVE-2020-24139 is a server-side request forgery (SSRF) vulnerability in Wcms 0.3.2 that allows attackers to make arbitrary HTTP requests from the vuln...

Apr 7, 2021
CVE-2025-68696
8.2

CVE-2025-68696 is a Server-Side Request Forgery (SSRF) vulnerability in the httparty Ruby gem that allows attackers to make unauthorized requests to i...

Dec 23, 2025
CVE-2025-8267
8.2

The ssrfcheck package versions before 1.2.0 are vulnerable to Server-Side Request Forgery (SSRF) due to an incomplete IP address denylist that fails t...

Jul 28, 2025
CVE-2025-8020
8.2

The private-ip npm package is vulnerable to Server-Side Request Forgery (SSRF) because it fails to properly validate multicast IP addresses (224.0.0.0...

Jul 23, 2025
CVE-2025-3192
8.2

This SSRF vulnerability in spatie/browsershot allows attackers to make the server request internal network resources, potentially exposing localhost d...

Apr 4, 2025
CVE-2025-2691
8.2

This SSRF vulnerability in nossrf versions before 1.0.4 allows attackers to bypass protection mechanisms by providing hostnames that resolve to local ...

Mar 23, 2025
CVE-2024-8977
8.2

This vulnerability allows Server-Side Request Forgery (SSRF) attacks against GitLab Enterprise Edition instances with Product Analytics Dashboard enab...

Oct 10, 2024
CVE-2022-40700
8.2

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability affecting multiple WordPress plugins and themes. It allows attackers to make una...

Jan 19, 2024
CVE-2023-46124
8.2

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the Fides privacy engineering platform. Attackers can upload malicious YAML f...

Oct 25, 2023
CVE-2023-41054
8.2

CVE-2023-41054 is a Server-Side Request Forgery (SSRF) vulnerability in LibreY's image_proxy.php that allows attackers to use the server as a proxy to...

Sep 4, 2023
CVE-2022-1592
8.2

This Server-Side Request Forgery (SSRF) vulnerability in the Scout application allows attackers to make the server send arbitrary HTTP requests to int...

May 5, 2022
CVE-2022-24129
8.2

This SSRF vulnerability in the Shibboleth Identity Provider OIDC OP plugin allows attackers to make arbitrary HTTP requests to third-party services by...

Feb 4, 2022
CVE-2025-22603
8.1

AutoGPT versions prior to beta-v0.4.2 contain a server-side request forgery (SSRF) vulnerability in the 'Send Web Request' component that fails to fil...

Mar 10, 2025

About Server-Side Request Forgery (SSRF) (CWE-918)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Our database tracks 803 CVEs classified as CWE-918, with 165 rated critical and 305 rated high severity. The average CVSS score for Server-Side Request Forgery (SSRF) vulnerabilities is 7.2.

External reference: View CWE-918 on MITRE CWE →

Monitor Server-Side Request Forgery (SSRF) Vulnerabilities

Get alerted when new Server-Side Request Forgery (SSRF) CVEs affect your infrastructure.

Start Monitoring Free