CWE-918: Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

804
Total CVEs
166
Critical
305
High
7.2
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
119
2025
340
2024
157
2023
60
2022
53

Top Affected Vendors

1 Microsoft 16
2 Apache 16
3 Ibm 9
4 Gitlab 7
5 Sap 6
6 Craftcms 5
7 Agpt 5
8 Maccms 5
9 Langchain 4
10 Progress 4

All Server-Side Request Forgery (SSRF) CVEs (804)

CVE-2025-64511
7.4

This vulnerability in MaxKB allows authenticated users to bypass sandbox restrictions and execute Python code that can access internal network service...

Nov 13, 2025
CVE-2025-5276
7.4

This SSRF vulnerability in mcp-markdownify-server allows attackers to craft prompts that trick the server into making HTTP requests to attacker-contro...

May 29, 2025
CVE-2024-38514
7.4

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in NextChat's WebDav API endpoint. Attackers can exploit it by manipulating the ...

Jun 28, 2024
CVE-2023-26459
7.4

This vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform allows authenticated non-administrative users to craft requests that trigger the app...

Mar 14, 2023
CVE-2026-3026
7.3

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the UEditor component of erzhongxmu JEEWMS 3.7. Attackers can exploit the /pl...

Feb 23, 2026
CVE-2025-15264
7.3

This vulnerability allows attackers to perform Server-Side Request Forgery (SSRF) attacks against FeehiCMS installations up to version 2.1.1. By manip...

Dec 30, 2025
CVE-2025-60541
7.3

This Server-Side Request Forgery (SSRF) vulnerability in prompt-optimizer allows attackers to make the server send requests to internal resources that...

Nov 6, 2025
CVE-2025-11864
7.3

This vulnerability allows remote attackers to perform server-side request forgery (SSRF) attacks against NucleoidAI Nucleoid servers. Attackers can ma...

Oct 16, 2025
CVE-2025-61735
7.3

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin that allows attackers to make unauthorized requests from the ser...

Oct 2, 2025
CVE-2025-45474
7.3

CVE-2025-45474 is a Server-Side Request Forgery (SSRF) vulnerability in maccms10's email settings functionality. Attackers can exploit this to make un...

May 29, 2025
CVE-2025-2243
7.3

A server-side request forgery (SSRF) vulnerability in Bitdefender GravityZone Console allows attackers to bypass input validation using leading charac...

Apr 4, 2025
CVE-2024-11618
7.3

This critical vulnerability in IPC Unigy Management System allows attackers to perform server-side request forgery (SSRF) through the HTTP Request Han...

Nov 22, 2024
CVE-2024-7742
7.3

This critical vulnerability in wanglongcn ltcms 1.0.20 allows remote attackers to perform server-side request forgery (SSRF) through the /api/file/mul...

Aug 13, 2024
CVE-2024-7740
7.3

This critical vulnerability in wanglongcn ltcms 1.0.20 allows attackers to perform server-side request forgery (SSRF) through the /api/test/download e...

Aug 13, 2024
CVE-2024-36448
7.3

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Apache IoTDB Workbench, allowing attackers to make unauthorized requests from...

Aug 5, 2024
CVE-2024-34581
7.3

This CVE highlights a Server-Side Request Forgery (SSRF) vulnerability in XML Digital Signature (XMLDsig) implementations due to insufficient warnings...

Jun 26, 2024
CVE-2024-1233
7.3

This vulnerability allows attackers to perform server-side request forgery (SSRF) attacks against JBoss EAP servers. When the JWT validator processes ...

Apr 9, 2024
CVE-2024-24806
7.3

A buffer truncation vulnerability in libuv's uv_getaddrinfo function allows attackers to craft malicious hostnames that resolve to unintended IP addre...

Feb 7, 2024
CVE-2024-0945
7.3

This critical vulnerability in 60IndexPage allows remote attackers to perform server-side request forgery (SSRF) by manipulating the 'url' parameter i...

Jan 26, 2024
CVE-2024-0510
7.3

This critical SSRF vulnerability in HaoKeKeJi YiQiNiu allows attackers to make unauthorized server-side HTTP requests to internal systems by manipulat...

Jan 13, 2024
CVE-2023-6849
7.3

This critical Server-Side Request Forgery (SSRF) vulnerability in kodbox allows attackers to manipulate the 'path' parameter in the cover function to ...

Dec 16, 2023
CVE-2026-1273
7.2

This Server-Side Request Forgery (SSRF) vulnerability in the PostX WordPress plugin allows authenticated attackers with Administrator privileges to ma...

Mar 4, 2026
CVE-2026-0745
7.2

The User Language Switch WordPress plugin contains a Server-Side Request Forgery (SSRF) vulnerability that allows authenticated administrators to make...

Feb 14, 2026
CVE-2026-1294
7.2

The All In One Image Viewer Block WordPress plugin has a Server-Side Request Forgery (SSRF) vulnerability that allows unauthenticated attackers to mak...

Feb 5, 2026
CVE-2025-14610
7.2

The TableMaster for Elementor WordPress plugin has a Server-Side Request Forgery (SSRF) vulnerability that allows authenticated attackers with Author-...

Jan 28, 2026
CVE-2025-68030
7.2

This Server-Side Request Forgery (SSRF) vulnerability in the WP Messiah Frontis Blocks WordPress plugin allows attackers to make unauthorized requests...

Jan 22, 2026
CVE-2025-14613
7.2

The GetContentFromURL WordPress plugin is vulnerable to Server-Side Request Forgery (SSRF) in all versions up to 1.0. This allows authenticated attack...

Jan 14, 2026
CVE-2025-13999
7.2

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the HTML5 Audio Player WordPress plugin. Unauthenticated attackers can exploi...

Dec 19, 2025
CVE-2021-47703
7.2

OpenBMCS 2.4 contains an unauthenticated Server-Side Request Forgery (SSRF) vulnerability that allows attackers to force the application to make HTTP ...

Dec 9, 2025
CVE-2025-58179
7.2

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Astro's Cloudflare adapter. When configured with output: 'server' and using t...

Sep 5, 2025
CVE-2025-7813
7.2

This vulnerability allows unauthenticated attackers to perform Server-Side Request Forgery (SSRF) attacks through the Eventin WordPress plugin. Attack...

Aug 23, 2025
CVE-2025-6851
7.2

The Broken Link Notifier WordPress plugin contains a Server-Side Request Forgery (SSRF) vulnerability that allows unauthenticated attackers to make ar...

Jul 11, 2025
CVE-2025-49418
7.2

This Server-Side Request Forgery (SSRF) vulnerability in the TeconceTheme Allmart WordPress plugin allows attackers to make the vulnerable server send...

Jul 4, 2025
CVE-2025-40595
7.2

An unauthenticated SSRF vulnerability in SMA1000 Appliance Work Place interface allows attackers to make the appliance send requests to arbitrary inte...

May 14, 2025
CVE-2025-2170
7.2

A Server-Side Request Forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface allows remote unauthenticated attackers to make the a...

Apr 30, 2025
CVE-2025-23082
7.2

Veeam Backup for Microsoft Azure is vulnerable to Server-Side Request Forgery (SSRF), allowing unauthenticated attackers to make unauthorized requests...

Jan 14, 2025
CVE-2024-55086
7.2

This SSRF vulnerability in GetSimple CMS CE 3.3.19 allows attackers to make the server send requests to internal systems through the plugin download f...

Dec 18, 2024
CVE-2024-54385
7.2

A Server-Side Request Forgery (SSRF) vulnerability in the SoftLab Radio Player WordPress plugin allows attackers to make unauthorized requests from th...

Dec 16, 2024
CVE-2024-54197
7.2

This vulnerability in SAP NetWeaver Administrator allows authenticated attackers to perform Server-Side Request Forgery (SSRF) by enumerating internal...

Dec 10, 2024
CVE-2022-1751
7.2

The Skitter Slideshow WordPress plugin contains a Server-Side Request Forgery (SSRF) vulnerability that allows unauthenticated attackers to make arbit...

Aug 17, 2024
CVE-2024-38728
7.2

This Server-Side Request Forgery (SSRF) vulnerability in the Seraphinite Post .DOCX Source WordPress plugin allows attackers to make unauthorized requ...

Jul 22, 2024
CVE-2024-37942
7.2

This CVE describes an unauthenticated Server-Side Request Forgery (SSRF) vulnerability in the BerqWP WordPress plugin. Attackers can exploit this to m...

Jul 22, 2024
CVE-2024-37260
7.2

This Server-Side Request Forgery (SSRF) vulnerability in the Foxiz WordPress theme allows attackers to make unauthorized requests from the vulnerable ...

Jul 6, 2024
CVE-2024-33250
7.2

This vulnerability allows remote attackers to execute arbitrary code on affected SRS real-time video servers by sending a specially crafted request. I...

May 14, 2024
CVE-2024-1812
7.2

The Everest Forms WordPress plugin has a Server-Side Request Forgery (SSRF) vulnerability that allows unauthenticated attackers to make arbitrary web ...

Apr 9, 2024
CVE-2024-31288
7.2

This Server-Side Request Forgery (SSRF) vulnerability in RapidLoad Power-Up for Autoptimize allows attackers to make the WordPress server send unautho...

Apr 7, 2024
CVE-2023-51441
7.2

This vulnerability in Apache Axis 1 allows authenticated users with admin service access to perform Server-Side Request Forgery (SSRF) attacks due to ...

Jan 6, 2024
CVE-2023-49159
7.2

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the WordPress CommentLuv plugin. Attackers can exploit this to make the vulne...

Dec 15, 2023
CVE-2023-27451
7.2

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the Darren Cooney Instant Images WordPress plugin. It allows authenticated at...

Nov 22, 2023
CVE-2021-35391
7.2

This Server-Side Request Forgery (SSRF) vulnerability in Deskpro Support Desk allows attackers to craft malicious URLs that trick the server into maki...

Jul 21, 2023

About Server-Side Request Forgery (SSRF) (CWE-918)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Our database tracks 804 CVEs classified as CWE-918, with 166 rated critical and 305 rated high severity. The average CVSS score for Server-Side Request Forgery (SSRF) vulnerabilities is 7.2.

External reference: View CWE-918 on MITRE CWE →

Monitor Server-Side Request Forgery (SSRF) Vulnerabilities

Get alerted when new Server-Side Request Forgery (SSRF) CVEs affect your infrastructure.

Start Monitoring Free