VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,681)

page 108 of 185
  • CVE-2023-40033HigAug 16, 2023
    risk 0.39cvss 7.1epss 0.01

    Flarum is an open source forum software. Flarum is affected by a vulnerability that allows an attacker to conduct a Blind Server-Side Request Forgery (SSRF) attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file…

  • CVE-2022-36551MedOct 3, 2022
    risk 0.39cvss 6.5epss 0.07

    A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.0 and earlier allows an authenticated user to access arbitrary files on the system. Furthermore, self-registration is enabled by default in these versions of…

  • CVE-2020-28978MedNov 30, 2020
    risk 0.39cvss 5.3epss 0.15

    The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/tree.php?subdomain=SSRF.

  • CVE-2020-28977MedNov 30, 2020
    risk 0.39cvss 5.3epss 0.15

    The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/get.php?subdomain=SSRF.

  • CVE-2020-6308MedOct 20, 2020
    risk 0.39cvss 5.3epss 0.62

    SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which is otherwise not accessible externally. On successful…

  • CVE-2019-6793HigSep 9, 2019
    risk 0.39cvss 7.0epss 0.04

    An issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The Jira integration feature is vulnerable to an unauthenticated blind SSRF issue.

  • CVE-2026-101910MedSep 28, 2026
    risk 0.38cvss —epss 0.00

    ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.2.0 until 10.5.1, the Address6 isPrivate classifier in src/ipv6.ts does not recognize the NAT64 local-use range 64:ff9b:1::/48. Applications that combine isPrivate, isLoopback,…

  • CVE-2026-90984MedSep 18, 2026
    risk 0.38cvss 5.8epss 0.00

    The Generate PDF using Contact Form 7 WordPress plugin before 4.2.2 does not restrict the destination of the image fetch its PDF renderer performs on submitted form content, allowing unauthenticated users to make the server request internal resources and read the response back…

  • CVE-2026-61793MedSep 17, 2026
    risk 0.38cvss —epss 0.01

    Nuxt OG Image generates OG Images with Vue templates in Nuxt. From 6.0.2 until 6.7.0, nuxt-og-image exposes the unauthenticated /_og/d/** route when the documented defaults security.strict = false and security.secret = "" are used, and base64url-decodes the fonts parameter…

  • CVE-2026-91966MedSep 15, 2026
    risk 0.38cvss 5.8epss 0.00

    AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the check_site_availability function that accepts attacker-controlled HTTP Host headers. Attackers can send requests to submitIndex.php or ajax.php with arbitrary Host headers to probe…

  • CVE-2026-85242MedSep 3, 2026
    risk 0.38cvss —epss 0.00

    PlaywrightCapture contains a server-side request forgery (SSRF) vulnerability in its favicon retrieval functionality. When only_global_lookup is enabled, the application validates the initial favicon URL to prevent requests to localhost, loopback, or other non-public network…

  • CVE-2026-62993MedAug 31, 2026
    risk 0.38cvss —epss 0.01

    Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 4.5.7 and 5.8.2, depending on the release line, Smarty's {fetch} handling in libs/plugins/function.fetch.php and src/FunctionHandler/Fetch.php used…

  • CVE-2026-55758MedAug 27, 2026
    risk 0.38cvss —epss 0.00

    CC: Tweaked is a mod for Minecraft which adds programmable computers, turtles, and more to the game. Prior to 1.120.0, the SSRF protection in projects/core/src/main/java/dan200/computercraft/core/apis/http/options/AddressPredicate.java blocks the RFC 6052 64:ff9b::/96 NAT64…

  • CVE-2026-78205MedAug 24, 2026
    risk 0.38cvss 5.8epss 0.00

    BentoML's outbound connection safeguard (make_safe_connect in _internal/utils/uri.py) blocks private, loopback, and link-local IP addresses but fails to reject the RFC 6598 shared address space (100.64.0.0/10, CGNAT). In versions 1.4.19 through 1.4.39, an unauthenticated…

  • CVE-2026-48053MedAug 17, 2026
    risk 0.38cvss 5.8epss 0.00

    Kolibri is an offline-first education platform. Prior to version 0.19.4, several Kolibri API endpoints accept an unvalidated `baseurl` parameter and fetch attacker-controlled URLs from the Kolibri server, reflecting the response body back to the caller. The original report…

  • CVE-2026-13700MedAug 17, 2026
    risk 0.38cvss 5.9epss 0.00

    The WooMS WordPress plugin through 9.14 does not validate a user-supplied URL before using it in a server-side request and attaches stored third-party integration credentials to every such request, allowing unauthenticated attackers to perform Server-Side Request Forgery and to…

  • CVE-2026-73297MedAug 12, 2026
    risk 0.38cvss —epss 0.03

    Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, _is_blocked_ip in ufo/utils/url_security.py did not block NAT64 prefixes 64:ff9b::/96 and 64:ff9b:1::/48, the 6to4 prefix 2002::/16, or the Teredo prefix 2001::/32 and…

  • CVE-2026-72761MedAug 10, 2026
    risk 0.38cvss —epss 0.00

    The webhook URL validator in `website/notifications/webhooks.py` uses `ip.is_global` to reject non-public addresses after DNS resolution. IPv6 transition addresses (NAT64 `64:ff9b::/96`, 6to4 `2002::/16`, Teredo `2001:0000::/32`) are classified as globally routable by IANA, so…

  • CVE-2026-70605MedAug 5, 2026
    risk 0.38cvss 5.9epss 0.00

    Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, when following HTTP redirects, net.fetch() and net.request() did not restrict which schemes a redirect could target. A…

  • CVE-2026-10526MedAug 4, 2026
    risk 0.38cvss 5.8epss 0.00

    The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests through unauthenticated endpoints, allowing unauthenticated attackers to induce the site to send HTTP requests to internal hosts and services that WordPress core…