VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,682)

page 104 of 185
  • CVE-2020-36862MedOct 30, 2025
    risk 0.40cvss 6.1epss 0.01

    Nagios XI versions prior to 5.6.11 contain unauthenticated vulnerabilities in the Highcharts local exporting tool. Crafted export requests could (1) inject script into exported/returned content due to insufficient output encoding (XSS), and (2) cause the server to fetch…

  • CVE-2025-59837HigOct 28, 2025
    risk 0.40cvss 7.2epss 0.00

    Astro is a web framework that includes an image proxy. In versions 5.13.4 and later before 5.13.10, the image proxy domain validation can be bypassed by using backslashes in the href parameter, allowing server-side requests to arbitrary URLs. This can lead to server-side request…

  • CVE-2025-61735HigOct 2, 2025
    risk 0.40cvss 7.3epss 0.01

    Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. This issue affects Apache Kylin: from 4.0.0 through 5.0.2. You are fine as long as the Kylin's system and project admin access is well protected. Users are recommended to upgrade to version 5.0.3, which fixes…

  • CVE-2025-58179HigSep 5, 2025
    risk 0.40cvss 7.2epss 0.01

    Astro is a web framework for content-driven websites. Versions 11.0.3 through 12.6.5 are vulnerable to SSRF when using Astro's Cloudflare adapter. When configured with output: 'server' while using the default imageService: 'compile', the generated image optimization endpoint…

  • CVE-2025-7813HigAug 23, 2025
    risk 0.40cvss 7.2epss 0.00

    The Events Calendar, Event Booking, Registrations and Event Tickets – Eventin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.37 via the proxy_image function. This makes it possible for unauthenticated attackers to…

  • CVE-2025-49545MedJul 8, 2025
    risk 0.40cvss 6.2epss 0.00

    ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. A high-privilege authenticated attacker can force the application to make arbitrary requests via injection…

  • CVE-2024-48346MedOct 30, 2024
    risk 0.40cvss 6.1epss 0.00

    xtreme1 <= v0.9.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the /api/data/upload path. The vulnerability is triggered through the fileUrl parameter, which allows an attacker to make arbitrary requests to internal or external systems.

  • CVE-2024-30125MedJul 18, 2024
    risk 0.40cvss 6.2epss 0.00

    HCL BigFix Compliance server can respond with an HTTP status of 500, indicating a server-side error that may cause the server process to die.

  • CVE-2024-39687HigJul 5, 2024
    risk 0.40cvss 7.2epss 0.01

    Fedify is a TypeScript library for building federated server apps powered by ActivityPub and other standards. At present, when Fedify needs to retrieve an object or activity from a remote activitypub server, it makes a HTTP request to the `@id` or other resources present within…

  • CVE-2024-3047HigMay 2, 2024
    risk 0.40cvss 7.2epss 0.00

    The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.8.0 via the transform() function. This can allow unauthenticated attackers to make web requests to arbitrary locations…

  • CVE-2023-7253MedApr 24, 2024
    risk 0.40cvss 6.1epss 0.01

    The Import WP WordPress plugin before 2.13.1 does not prevent users with the administrator role from pinging conducting SSRF attacks, which may be a problem in multisite configurations.

  • CVE-2024-1812HigApr 9, 2024
    risk 0.40cvss 7.2epss 0.01

    The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.0.7 via the 'font_url' parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web…

  • CVE-2024-28668MedMar 13, 2024
    risk 0.40cvss 6.1epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/mychannel_add.php

  • CVE-2023-51441HigJan 6, 2024
    risk 0.40cvss 7.2epss 0.01

    ** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Axis allowed users with access to the admin service to perform possible SSRF This issue affects Apache Axis: through 1.3. As Axis 1 has been EOL we recommend you migrate to a different SOAP…

  • CVE-2023-40969MedSep 1, 2023
    risk 0.40cvss 6.1epss 0.00

    Senayan Library Management Systems SLIMS 9 Bulian v9.6.1 is vulnerable to Server Side Request Forgery (SSRF) via admin/modules/bibliography/pop_p2p.php.

  • CVE-2021-42079MedJul 10, 2023
    risk 0.40cvss 6.2epss 0.01

    An authenticated administrator is able to prepare an alert that is able to execute an SSRF attack. This is exclusively with POST requests. POC Step 1: Prepare the SSRF with a request like this: GET /qstorapi/alertConfigSet?senderEmailAddress=a&smtpServerIpAddress=BURPCOLLABHOS…

  • CVE-2022-24969MedJun 9, 2022
    risk 0.40cvss 6.1epss 0.02

    bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check which can cause open redirect or SSRF vulnerability.

  • CVE-2022-24871HigApr 20, 2022
    risk 0.40cvss 7.2epss 0.01

    Shopware is an open commerce platform based on Symfony Framework and Vue. In affected versions an attacker can abuse the Admin SDK functionality on the server to read or update internal resources. Users are advised to update to the current version 6.4.10.1. For older versions of…

  • CVE-2021-4075HigDec 6, 2021
    risk 0.40cvss 7.2epss 0.01

    snipe-it is vulnerable to Server-Side Request Forgery (SSRF)

  • CVE-2021-25640MedJun 1, 2021
    risk 0.40cvss 6.1epss 0.02

    In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which can cause open redirect or SSRF vulnerability.