CWE-918: Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

803
Total CVEs
165
Critical
305
High
7.2
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
118
2025
340
2024
157
2023
60
2022
53

Top Affected Vendors

1 Microsoft 16
2 Apache 16
3 Ibm 9
4 Gitlab 7
5 Sap 6
6 Craftcms 5
7 Agpt 5
8 Maccms 5
9 Langchain 4
10 Progress 4

All Server-Side Request Forgery (SSRF) CVEs (803)

CVE-2024-32965
8.1

Lobe Chat versions before 1.19.13 have an unauthenticated SSRF vulnerability that allows attackers to send malicious requests to internal network serv...

Nov 26, 2024
CVE-2024-48178
8.1

CVE-2024-48178 is a Server-Side Request Forgery (SSRF) vulnerability in newbee-mall v1.0.0 that allows attackers to make the server send unauthorized ...

Oct 28, 2024
CVE-2024-41651
8.1

This vulnerability in PrestaShop allows remote code execution through the module upgrade functionality. It affects PrestaShop versions 8.1.7 and earli...

Aug 12, 2024
CVE-2024-29415
8.1

The ip package through version 2.0.1 for Node.js improperly categorizes certain IP address formats (like 127.1, 01200034567, and IPv6 variations) as g...

May 27, 2024
CVE-2024-22873
8.1

Tencent Blueking CMDB versions 3.2.x to 3.9.x contain a Server-Side Request Forgery (SSRF) vulnerability in the event subscription function. Attackers...

Feb 26, 2024
CVE-2024-0243
8.1

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in LangChain's RecursiveUrlLoader where an attacker controlling the initial craw...

Feb 26, 2024
CVE-2024-23788
8.1

This CVE describes a server-side request forgery (SSRF) vulnerability in Sharp Energy Management Controllers. An unauthenticated attacker on the same ...

Feb 14, 2024
CVE-2023-46725
8.1

FoodCoopShop versions 3.2.0 through 3.6.0 contain a server-side request forgery (SSRF) vulnerability in the Network module. Manufacturer accounts can ...

Nov 2, 2023
CVE-2023-23955
8.1

This Server-Side Request Forgery vulnerability in Broadcom's Advanced Secure Gateway and Content Analysis allows attackers to make the vulnerable serv...

Jun 1, 2023
CVE-2020-22983
8.1

This Server-Side Request Forgery (SSRF) vulnerability in MicroStrategy Web SDK allows remote unauthenticated attackers to make the server send HTTP re...

May 13, 2022
CVE-2021-39057
8.1

CVE-2021-39057 is a server-side request forgery (SSRF) vulnerability in IBM Spectrum Protect Plus that allows authenticated attackers to make unauthor...

Dec 13, 2021
CVE-2021-33705
8.1

CVE-2021-33705 is a Server-Side Request Forgery (SSRF) vulnerability in SAP NetWeaver Portal's Iviews Editor component that allows unauthenticated att...

Sep 15, 2021
CVE-2021-22726
8.1

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Schneider Electric EVlink electric vehicle charging stations. An attacker can...

Jul 21, 2021
CVE-2021-31216
8.1

CVE-2021-31216 is a server-side request forgery (SSRF) vulnerability in Siren Investigate's built-in image proxy route that allows authenticated attac...

Jul 19, 2021
CVE-2025-22399
7.9

Dell UCC Edge version 2.3.0 contains a blind Server-Side Request Forgery (SSRF) vulnerability in the Add Customer SFTP Server functionality. Unauthent...

Feb 11, 2025
CVE-2023-42361
7.8

This Local File Inclusion vulnerability in Midori-global Better PDF Exporter for Jira allows attackers to read arbitrary files on the server by upload...

Nov 7, 2023
CVE-2026-27706
7.7

Plane project management tool versions before 1.2.2 contain a Full Read SSRF vulnerability in the 'Add Link' feature. Authenticated users can send arb...

Feb 25, 2026
CVE-2026-27479
7.7

Wallos versions 4.6.0 and below contain a Server-Side Request Forgery (SSRF) vulnerability in the logo/icon upload functionality. Attackers can bypass...

Feb 21, 2026
CVE-2026-25991
7.7

CVE-2026-25991 is a Blind Server-Side Request Forgery (SSRF) vulnerability in Tandoor Recipes that allows authenticated users to make the server conne...

Feb 13, 2026
CVE-2026-22219
7.7

This CVE describes a server-side request forgery (SSRF) vulnerability in Chainlit versions before 2.9.4 when using the SQLAlchemy data layer backend. ...

Jan 20, 2026
CVE-2026-21433
7.7

Emlog versions up to 2.5.19 are vulnerable to server-side request forgery (SSRF) via malicious SVG file uploads. Attackers can upload crafted SVG file...

Jan 2, 2026
CVE-2025-26494
7.7

A Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server versions 2023.3 through 2023.3.5 allows attackers to bypass authentica...

Feb 11, 2025
CVE-2025-0474
7.7

Invoice Ninja versions 5.8.56 through 5.11.23 contain an authenticated Server-Side Request Forgery (SSRF) vulnerability that allows authenticated user...

Jan 14, 2025
CVE-2024-49521
7.7

Adobe Commerce versions 3.2.5 and earlier contain a Server-Side Request Forgery (SSRF) vulnerability that allows low-privileged attackers to send craf...

Nov 12, 2024
CVE-2024-8635
7.7

A server-side request forgery (SSRF) vulnerability in GitLab EE allows attackers to make requests to internal resources via a custom Maven Dependency ...

Sep 12, 2024
CVE-2024-36414
7.7

This vulnerability in SuiteCRM allows attackers to perform server-side request forgery (SSRF) attacks through the connectors file verification feature...

Jun 10, 2024
CVE-2024-3095
7.7

This Server-Side Request Forgery (SSRF) vulnerability in langchain's Web Research Retriever allows attackers to make the server send requests to inter...

Jun 6, 2024
CVE-2024-23500
7.7

This Server-Side Request Forgery (SSRF) vulnerability in Kadence WP Gutenberg Blocks allows attackers to make unauthorized requests from the WordPress...

Mar 28, 2024
CVE-2021-39195
7.7

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Misskey's 'Upload from URL' and remote attachment features. Attackers can exp...

Sep 7, 2021
CVE-2021-22255
7.7

This vulnerability allows authenticated users in Baserow to perform Server-Side Request Forgery (SSRF) attacks via URL file upload functionality. Atta...

Aug 20, 2021
CVE-2021-21287
7.7

This CVE describes a server-side request forgery (SSRF) vulnerability in MinIO object storage software. Attackers can manipulate URL parameters to mak...

Feb 1, 2021
CVE-2025-68662
7.6

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Discourse's FinalDestination component where hostname validation can be bypas...

Jan 28, 2026
CVE-2025-33203
7.6

This vulnerability in NVIDIA NeMo Agent Toolkit UI for Web allows attackers to perform Server-Side Request Forgery (SSRF) through the chat API endpoin...

Nov 25, 2025
CVE-2024-13957
7.6

This SSRF vulnerability in ABB ASPECT, NEXUS, and MATRIX series allows attackers to make unauthorized requests from the server to internal systems whe...

May 22, 2025
CVE-2025-29457
7.6

This vulnerability in MyBB 1.8.38 allows remote attackers to obtain sensitive information through the Import a Theme function, potentially via Server-...

Apr 17, 2025
CVE-2025-29459
7.6

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in MyBB 1.8.38's Mail function that could allow attackers to access internal net...

Apr 17, 2025
CVE-2025-29461
7.6

This vulnerability in a-blogcms 3.1.15 allows remote attackers to access sensitive information through the /bid/1/admin/entry-edit/ path. It affects a...

Apr 17, 2025
CVE-2025-29451
7.6

This vulnerability in Seo Panel 4.11.0 allows remote attackers to access sensitive information through the Mail Setting component. The issue enables u...

Apr 17, 2025
CVE-2025-1912
7.6

This Server-Side Request Forgery (SSRF) vulnerability in the Product Import Export for WooCommerce plugin allows authenticated WordPress administrator...

Mar 26, 2025
CVE-2025-1970
7.6

This Server-Side Request Forgery vulnerability in the Export and Import Users and Customers WordPress plugin allows authenticated administrators to ma...

Mar 22, 2025
CVE-2024-13923
7.6

This vulnerability allows authenticated WordPress administrators to perform Server-Side Request Forgery (SSRF) attacks through the Order Export & Orde...

Mar 20, 2025
CVE-2024-9624
7.6

The WP All Import Pro WordPress plugin has a Server-Side Request Forgery vulnerability that allows authenticated attackers with Administrator privileg...

Dec 17, 2024
CVE-2024-5746
7.6

A Server-Side Request Forgery vulnerability in GitHub Enterprise Server allows authenticated site administrators to execute arbitrary code on the serv...

Jun 20, 2024
CVE-2023-44313
7.6

This Server-Side Request Forgery (SSRF) vulnerability in Apache ServiceComb Service-Center allows attackers to send specially crafted requests that tr...

Jan 31, 2024
CVE-2024-22408
7.6

This vulnerability in Shopware's Flow Builder allows attackers to bypass URL validation in webhook actions, enabling Server-Side Request Forgery (SSRF...

Jan 16, 2024
CVE-2022-24789
7.6

CVE-2022-24789 is a Server-Side Request Forgery (SSRF) vulnerability in C1 CMS that allows authenticated users to make arbitrary GET requests to inter...

Mar 28, 2022
CVE-2021-31950
7.6

CVE-2021-31950 is a server-side request forgery (SSRF) vulnerability in Microsoft SharePoint Server that allows authenticated attackers to send crafte...

Jun 8, 2021
CVE-2026-27730
7.5

CVE-2026-27730 is a Server-Side Request Forgery (SSRF) vulnerability in esm.sh's fetch route that allows attackers to bypass hostname-based validation...

Feb 25, 2026
CVE-2026-26324
7.5

OpenClaw's SSRF protection could be bypassed using IPv4-mapped IPv6 addresses, allowing attackers to access restricted internal resources like localho...

Feb 19, 2026
CVE-2026-24138
7.5

CVE-2026-24138 is an unauthenticated Server-Side Request Forgery (SSRF) vulnerability in FOG Project's getversion.php. Attackers can exploit this by s...

Jan 23, 2026

About Server-Side Request Forgery (SSRF) (CWE-918)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Our database tracks 803 CVEs classified as CWE-918, with 165 rated critical and 305 rated high severity. The average CVSS score for Server-Side Request Forgery (SSRF) vulnerabilities is 7.2.

External reference: View CWE-918 on MITRE CWE →

Monitor Server-Side Request Forgery (SSRF) Vulnerabilities

Get alerted when new Server-Side Request Forgery (SSRF) CVEs affect your infrastructure.

Start Monitoring Free