CWE-918: Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Yearly Trend
Top Affected Vendors
All Server-Side Request Forgery (SSRF) CVEs (803)
Lobe Chat versions before 1.19.13 have an unauthenticated SSRF vulnerability that allows attackers to send malicious requests to internal network serv...
Nov 26, 2024CVE-2024-48178 is a Server-Side Request Forgery (SSRF) vulnerability in newbee-mall v1.0.0 that allows attackers to make the server send unauthorized ...
Oct 28, 2024This vulnerability in PrestaShop allows remote code execution through the module upgrade functionality. It affects PrestaShop versions 8.1.7 and earli...
Aug 12, 2024The ip package through version 2.0.1 for Node.js improperly categorizes certain IP address formats (like 127.1, 01200034567, and IPv6 variations) as g...
May 27, 2024Tencent Blueking CMDB versions 3.2.x to 3.9.x contain a Server-Side Request Forgery (SSRF) vulnerability in the event subscription function. Attackers...
Feb 26, 2024This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in LangChain's RecursiveUrlLoader where an attacker controlling the initial craw...
Feb 26, 2024This CVE describes a server-side request forgery (SSRF) vulnerability in Sharp Energy Management Controllers. An unauthenticated attacker on the same ...
Feb 14, 2024FoodCoopShop versions 3.2.0 through 3.6.0 contain a server-side request forgery (SSRF) vulnerability in the Network module. Manufacturer accounts can ...
Nov 2, 2023This Server-Side Request Forgery vulnerability in Broadcom's Advanced Secure Gateway and Content Analysis allows attackers to make the vulnerable serv...
Jun 1, 2023This Server-Side Request Forgery (SSRF) vulnerability in MicroStrategy Web SDK allows remote unauthenticated attackers to make the server send HTTP re...
May 13, 2022CVE-2021-39057 is a server-side request forgery (SSRF) vulnerability in IBM Spectrum Protect Plus that allows authenticated attackers to make unauthor...
Dec 13, 2021CVE-2021-33705 is a Server-Side Request Forgery (SSRF) vulnerability in SAP NetWeaver Portal's Iviews Editor component that allows unauthenticated att...
Sep 15, 2021This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Schneider Electric EVlink electric vehicle charging stations. An attacker can...
Jul 21, 2021CVE-2021-31216 is a server-side request forgery (SSRF) vulnerability in Siren Investigate's built-in image proxy route that allows authenticated attac...
Jul 19, 2021Dell UCC Edge version 2.3.0 contains a blind Server-Side Request Forgery (SSRF) vulnerability in the Add Customer SFTP Server functionality. Unauthent...
Feb 11, 2025This Local File Inclusion vulnerability in Midori-global Better PDF Exporter for Jira allows attackers to read arbitrary files on the server by upload...
Nov 7, 2023Plane project management tool versions before 1.2.2 contain a Full Read SSRF vulnerability in the 'Add Link' feature. Authenticated users can send arb...
Feb 25, 2026Wallos versions 4.6.0 and below contain a Server-Side Request Forgery (SSRF) vulnerability in the logo/icon upload functionality. Attackers can bypass...
Feb 21, 2026CVE-2026-25991 is a Blind Server-Side Request Forgery (SSRF) vulnerability in Tandoor Recipes that allows authenticated users to make the server conne...
Feb 13, 2026This CVE describes a server-side request forgery (SSRF) vulnerability in Chainlit versions before 2.9.4 when using the SQLAlchemy data layer backend. ...
Jan 20, 2026Emlog versions up to 2.5.19 are vulnerable to server-side request forgery (SSRF) via malicious SVG file uploads. Attackers can upload crafted SVG file...
Jan 2, 2026A Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server versions 2023.3 through 2023.3.5 allows attackers to bypass authentica...
Feb 11, 2025Invoice Ninja versions 5.8.56 through 5.11.23 contain an authenticated Server-Side Request Forgery (SSRF) vulnerability that allows authenticated user...
Jan 14, 2025Adobe Commerce versions 3.2.5 and earlier contain a Server-Side Request Forgery (SSRF) vulnerability that allows low-privileged attackers to send craf...
Nov 12, 2024A server-side request forgery (SSRF) vulnerability in GitLab EE allows attackers to make requests to internal resources via a custom Maven Dependency ...
Sep 12, 2024This vulnerability in SuiteCRM allows attackers to perform server-side request forgery (SSRF) attacks through the connectors file verification feature...
Jun 10, 2024This Server-Side Request Forgery (SSRF) vulnerability in langchain's Web Research Retriever allows attackers to make the server send requests to inter...
Jun 6, 2024This Server-Side Request Forgery (SSRF) vulnerability in Kadence WP Gutenberg Blocks allows attackers to make unauthorized requests from the WordPress...
Mar 28, 2024This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Misskey's 'Upload from URL' and remote attachment features. Attackers can exp...
Sep 7, 2021This vulnerability allows authenticated users in Baserow to perform Server-Side Request Forgery (SSRF) attacks via URL file upload functionality. Atta...
Aug 20, 2021This CVE describes a server-side request forgery (SSRF) vulnerability in MinIO object storage software. Attackers can manipulate URL parameters to mak...
Feb 1, 2021This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Discourse's FinalDestination component where hostname validation can be bypas...
Jan 28, 2026This vulnerability in NVIDIA NeMo Agent Toolkit UI for Web allows attackers to perform Server-Side Request Forgery (SSRF) through the chat API endpoin...
Nov 25, 2025This SSRF vulnerability in ABB ASPECT, NEXUS, and MATRIX series allows attackers to make unauthorized requests from the server to internal systems whe...
May 22, 2025This vulnerability in MyBB 1.8.38 allows remote attackers to obtain sensitive information through the Import a Theme function, potentially via Server-...
Apr 17, 2025This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in MyBB 1.8.38's Mail function that could allow attackers to access internal net...
Apr 17, 2025This vulnerability in a-blogcms 3.1.15 allows remote attackers to access sensitive information through the /bid/1/admin/entry-edit/ path. It affects a...
Apr 17, 2025This vulnerability in Seo Panel 4.11.0 allows remote attackers to access sensitive information through the Mail Setting component. The issue enables u...
Apr 17, 2025This Server-Side Request Forgery (SSRF) vulnerability in the Product Import Export for WooCommerce plugin allows authenticated WordPress administrator...
Mar 26, 2025This Server-Side Request Forgery vulnerability in the Export and Import Users and Customers WordPress plugin allows authenticated administrators to ma...
Mar 22, 2025This vulnerability allows authenticated WordPress administrators to perform Server-Side Request Forgery (SSRF) attacks through the Order Export & Orde...
Mar 20, 2025The WP All Import Pro WordPress plugin has a Server-Side Request Forgery vulnerability that allows authenticated attackers with Administrator privileg...
Dec 17, 2024A Server-Side Request Forgery vulnerability in GitHub Enterprise Server allows authenticated site administrators to execute arbitrary code on the serv...
Jun 20, 2024This Server-Side Request Forgery (SSRF) vulnerability in Apache ServiceComb Service-Center allows attackers to send specially crafted requests that tr...
Jan 31, 2024This vulnerability in Shopware's Flow Builder allows attackers to bypass URL validation in webhook actions, enabling Server-Side Request Forgery (SSRF...
Jan 16, 2024CVE-2022-24789 is a Server-Side Request Forgery (SSRF) vulnerability in C1 CMS that allows authenticated users to make arbitrary GET requests to inter...
Mar 28, 2022CVE-2021-31950 is a server-side request forgery (SSRF) vulnerability in Microsoft SharePoint Server that allows authenticated attackers to send crafte...
Jun 8, 2021CVE-2026-27730 is a Server-Side Request Forgery (SSRF) vulnerability in esm.sh's fetch route that allows attackers to bypass hostname-based validation...
Feb 25, 2026OpenClaw's SSRF protection could be bypassed using IPv4-mapped IPv6 addresses, allowing attackers to access restricted internal resources like localho...
Feb 19, 2026CVE-2026-24138 is an unauthenticated Server-Side Request Forgery (SSRF) vulnerability in FOG Project's getversion.php. Attackers can exploit this by s...
Jan 23, 2026About Server-Side Request Forgery (SSRF) (CWE-918)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Our database tracks 803 CVEs classified as CWE-918, with 165 rated critical and 305 rated high severity. The average CVSS score for Server-Side Request Forgery (SSRF) vulnerabilities is 7.2.
External reference: View CWE-918 on MITRE CWE →
Monitor Server-Side Request Forgery (SSRF) Vulnerabilities
Get alerted when new Server-Side Request Forgery (SSRF) CVEs affect your infrastructure.
Start Monitoring Free