VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,680)

page 136 of 184
  • CVE-2025-62763MedOct 21, 2025
    risk 0.33cvss 5.0epss 0.00

    Zimbra Collaboration (ZCS) before 10.1.12 allows SSRF because of the configuration of the chat proxy.

  • CVE-2025-11536MedOct 20, 2025
    risk 0.33cvss 5.0epss 0.00

    The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 8.2.5 via the wp_ajax_import_elementor_template action. This makes it possible for authenticated attackers, with Subscriber-level…

  • CVE-2025-61768MedOct 6, 2025
    risk 0.33cvss —epss 0.00

    KUNO CMS is a fully deployable full-stack blog application. In versions prior to 1.3.15, an SSRF (Server-Side Request Forgery) vulnerability exists in the Media module of the Kuno CMS administrative panel. A logged-in administrator can upload a specially crafted SVG file…

  • CVE-2025-9799MedSep 1, 2025
    risk 0.33cvss 5.0epss 0.00

    A security flaw has been discovered in Langfuse up to 3.88.0. Affected by this vulnerability is the function promptChangeEventSourcing of the file web/src/features/prompts/server/routers/promptRouter.ts of the component Webhook Handler. Performing manipulation results in…

  • CVE-2024-46413MedAug 25, 2025
    risk 0.33cvss 5.1epss 0.00

    Rebuild v3.7.7 was discovered to contain a Server-Side Request Forgery (SSRF) via the type parameter in the com.rebuild.web.admin.rbstore.RBStoreController#loadDataIndex method.

  • CVE-2025-4655MedAug 9, 2025
    risk 0.33cvss 5.0epss 0.00

    SSRF vulnerability in FreeMarker templates in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15, 7.4 GA through update 92…

  • CVE-2023-35817MedApr 28, 2025
    risk 0.33cvss 5.0epss 0.00

    DevExpress before 23.1.3 allows AsyncDownloader SSRF.

  • CVE-2025-32102MedApr 15, 2025
    risk 0.33cvss 5.0epss 0.09

    CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows SSRF via the host and port parameters in a command=telnetSocket request to the /WebInterface/function/ URI.

  • CVE-2024-41737MedAug 13, 2024
    risk 0.33cvss 5.0epss 0.00

    SAP CRM ABAP (Insights Management) allows an authenticated attacker to enumerate HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in information disclosure. It has no impact on integrity and availability of…

  • CVE-2024-36458MedJul 15, 2024
    risk 0.33cvss —epss 0.00

    The vulnerability allows a malicious low-privileged PAM user to perform server upgrade related actions.

  • CVE-2024-37171MedJul 9, 2024
    risk 0.33cvss 5.0epss 0.00

    SAP Transportation Management (Collaboration Portal) allows an attacker with non-administrative privileges to send a crafted request from a vulnerable web application. This will trigger the application handler to send a request to an unintended service, which may reveal…

  • CVE-2024-34689MedJul 9, 2024
    risk 0.33cvss 5.0epss 0.00

    WebFlow Services of SAP Business Workflow allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in information disclosure. It has no impact on integrity and…

  • CVE-2024-39598MedJul 9, 2024
    risk 0.33cvss 5.0epss 0.00

    SAP CRM (WebClient UI Framework) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in information disclosure. It has no impact on integrity and…

  • CVE-2024-0862MedMay 14, 2024
    risk 0.33cvss 5.0epss 0.00

    The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains a Server-Side Request Forgery vulnerability that allows an authenticated user to relay HTTP requests from the Protection server to otherwise private network addresses.

  • CVE-2024-33590MedApr 29, 2024
    risk 0.33cvss 5.0epss 0.00

    Server-Side Request Forgery (SSRF) vulnerability in codeSavory Knowledge Base documentation & wiki plugin – BasePress.This issue affects Knowledge Base documentation & wiki plugin – BasePress: from n/a through 2.16.1.

  • CVE-2024-29029MedApr 19, 2024
    risk 0.33cvss 6.1epss 0.01

    memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that allows unauthenticated users to enumerate the internal network and retrieve images. The response from the image request is then copied into the…

  • CVE-2024-3448MedApr 10, 2024
    risk 0.33cvss 5.0epss 0.00

    Users with low privileges can perform certain AJAX actions. In this vulnerability instance, improper access to ajax?action=plugin:focus:checkIframeAvailability leads to a Server-Side Request Forgery by analyzing the error messages returned from the back-end. Allowing an…

  • CVE-2024-0677MedMar 28, 2024
    risk 0.33cvss 5.1epss 0.00

    The Pz-LinkCard WordPress plugin through 2.5.1 does not prevent users from pinging arbitrary hosts via some of its shortcodes, which could allow high privilege users such as contributors to perform SSRF attacks.

  • CVE-2023-5122MedFeb 14, 2024
    risk 0.33cvss 5.0epss 0.01

    Grafana is an open-source platform for monitoring and observability. The CSV datasource plugin is a Grafana Labs maintained plugin for Grafana that allows for retrieving and processing CSV data from a remote endpoint configured by an administrator. If this plugin was configured…

  • CVE-2023-6388MedFeb 7, 2024
    risk 0.33cvss 5.0epss 0.00

    Suite CRM version 7.14.2 allows making arbitrary HTTP requests through the vulnerable server. This is possible because the application is vulnerable to SSRF.