VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,632)

page 14 of 182
  • CVE-2019-12994CriAug 8, 2019
    risk 0.60cvss 9.1epss 0.04

    Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer version 6.2.0 for the AJaxServlet servlet via a parameter in a URL.

  • CVE-2017-15644HigOct 19, 2017
    risk 0.60cvss 8.6epss 0.09

    SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/http://INTRANET-IP:8000.

  • CVE-2016-6483HigSep 2, 2016
    risk 0.60cvss 8.6epss 0.12

    The media-file upload feature in vBulletin before 3.8.7 Patch Level 6, 3.8.8 before Patch Level 2, 3.8.9 before Patch Level 1, 4.x before 4.2.2 Patch Level 6, 4.2.3 before Patch Level 2, 5.x before 5.2.0 Patch Level 3, 5.2.1 before Patch Level 1, and 5.2.2 before Patch Level 1…

  • CVE-2026-80181CriSep 4, 2026
    risk 0.59cvss 9.1epss 0.00

    Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to version 1.21.0, which fixes the issue.

  • CVE-2026-51152CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.00

    Server-side request forgery (SSRF) in the /har/test endpoint in QD 20220208 through 20250803. Fetcher.build_request() in libs/fetcher.py constructs an httpclient.HTTPRequest from user-supplied JSON without validating URL scheme, host, or IP range. The /har/test handler does not…

  • CVE-2026-16947CriAug 29, 2026
    risk 0.59cvss 9.1epss 0.00

    The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path before using it to build a server-side verification request, and does not verify the authenticity of the response, allowing unauthenticated attackers to…

  • CVE-2026-75340CriAug 26, 2026
    risk 0.59cvss 9.1epss 0.00

    The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11 is vulnerable to Server-side request forgery (SSRF).

  • CVE-2026-75332CriAug 26, 2026
    risk 0.59cvss 9.1epss 0.00

    Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via WikiPageWebService.download().

  • CVE-2026-59085CriAug 21, 2026
    risk 0.59cvss 9.1epss 0.00

    Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook delivery requests. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to…

  • CVE-2026-69223CriAug 11, 2026
    risk 0.59cvss 9.1epss 0.01

    Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.

  • CVE-2026-19516CriAug 11, 2026
    risk 0.59cvss 9.1epss 0.00

    A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the caller also choose the HTTP method, path, and body. Because the destination is not restricted to the configured Grafana instance,…

  • CVE-2026-45262criJul 14, 2026
    risk 0.59cvss —epss —

    ## Summary > **Live PoC verified 2026-04-30** against a stock FacturaScripts master at `127.0.0.1:8081`. A scoped `ApiKey` with `fullaccess=0` and an `ApiAccess` row granting `allowget=1` on the `clientes` resource only (no other rights, no UI session, no admin) issued one `GET…

  • CVE-2026-56348CriJun 22, 2026
    risk 0.59cvss 9.1epss 0.00

    n8n before 2.20.0 contains a credential exfiltration vulnerability in the POST /rest/dynamic-node-parameters/options endpoint that allows authenticated users to bypass Allowed HTTP Request Domains restrictions. Attackers with credential access can cause the n8n server to issue…

  • CVE-2026-50887CriJun 15, 2026
    risk 0.59cvss 9.1epss 0.00

    A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink v5.0.1 allows attackers to scan internal resources via supplying a crafted longUrl.

  • CVE-2026-0258CriMay 13, 2026
    risk 0.59cvss 9.1epss 0.00

    A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software allows an unauthenticated attacker to cause the firewall to send network requests to unintended destinations or cause a denial of service (DoS) condition. …

  • CVE-2026-31017CriApr 8, 2026
    risk 0.59cvss 9.1epss 0.00

    A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where user-supplied HTML is insufficiently sanitized before being rendered into PDF. When generating PDFs from user-controlled HTML…

  • CVE-2023-46945CriApr 8, 2026
    risk 0.59cvss 9.1epss 0.00

    QD 20230821 is vulnerable to Server-side request forgery (SSRF) via a crafted request

  • CVE-2026-32133CriMar 11, 2026
    risk 0.59cvss 9.1epss 0.01

    2FAuth is a web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Prior to 6.1.0, a blind SSRF vulnerability exists in 2FAuth that allows authenticated users to make arbitrary HTTP requests from the server to internal networks and cloud…

  • CVE-2025-50199CriMar 2, 2026
    risk 0.59cvss 9.1epss 0.00

    Chamilo is a learning management system. Prior to version 1.11.30, there is a blind SSRF vulnerability in /index.php via the POST openid_url parameter. This issue has been patched in version 1.11.30.

  • CVE-2025-55853CriFeb 19, 2026
    risk 0.59cvss 9.1epss 0.00

    SoftVision webPDF before 10.0.2 is vulnerable to Server-Side Request Forgery (SSRF). The PDF converter function does not check if internal or external resources are requested in the uploaded files and allows for protocols such as http:// and file:///. This allows an attacker to…