CWE-918
Server-Side Request Forgery (SSRF)
Description
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-664
CVEs mapped to this weakness (3,632)
page 15 of 182| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-50199 | Cri | 0.59 | 9.1 | 0.00 | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is a blind SSRF vulnerability in /index.php via the POST openid_url parameter. This issue has been patched in version 1.11.30. | ||
| CVE-2025-55853 | Cri | 0.59 | 9.1 | 0.00 | Feb 19, 2026 | SoftVision webPDF before 10.0.2 is vulnerable to Server-Side Request Forgery (SSRF). The PDF converter function does not check if internal or external resources are requested in the uploaded files and allows for protocols such as http:// and file:///. This allows an attacker to… | ||
| CVE-2026-24736 | Cri | 0.59 | 9.1 | 0.00 | Jan 27, 2026 | Squidex is an open source headless content management system and content management hub. Versions of the application up to and including 7.21.0 allow users to define "Webhooks" as actions within the Rules engine. The url parameter in the webhook configuration does not appear to… | ||
| CVE-2024-25181 | Cri | 0.59 | 9.1 | 0.00 | Dec 29, 2025 | A critical vulnerability has been identified in givanz VvvebJs 1.7.2, which allows both Server-Side Request Forgery (SSRF) and arbitrary file reading. The vulnerability stems from improper handling of user-supplied URLs in the "file_get_contents" function within the "save.php"… | ||
| CVE-2025-66844 | Cri | 0.59 | 9.1 | 0.00 | Dec 15, 2025 | In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig and the configuration allows undefined PHP functions to be registered | ||
| CVE-2025-13872 | Cri | 0.59 | 9.1 | 0.00 | Dec 2, 2025 | Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on Web-based platforms allows an attacker to force the server to perform HTTP GET requests via crafted import requests to an arbitrary destination. | ||
| CVE-2025-65836 | Cri | 0.59 | 9.1 | 0.00 | Dec 1, 2025 | PublicCMS V5.202506.b is vulnerable to SSRF. in the chat interface of SimpleAiAdminController. | ||
| CVE-2025-57644 | Cri | 0.59 | 9.1 | 0.01 | Sep 19, 2025 | Accela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script feature. An authenticated administrative user can execute arbitrary Java code on the server, resulting in remote code execution. In addition, improper input validation allows for… | ||
| CVE-2025-44594 | Cri | 0.59 | 9.1 | 0.00 | Sep 9, 2025 | halo v2.20.17 and before is vulnerable to server-side request forgery (SSRF) in /apis/uc.api.storage.halo.run/v1alpha1/attachments/-/upload-from-url. | ||
| CVE-2025-27217 | Cri | 0.59 | 9.1 | 0.00 | Aug 21, 2025 | A Server-Side Request Forgery (SSRF) in the UISP Application may allow a malicious actor with certain permissions to make requests outside of UISP Application scope. | ||
| CVE-2025-50251 | Cri | 0.59 | 9.1 | 0.00 | Aug 13, 2025 | Server side request forgery (SSRF) vulnerability in makeplane plane 0.23.1 via the password recovery. | ||
| CVE-2025-54381 | Cri | 0.59 | 9.9 | 0.15 | Jul 29, 2025 | BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1.4.0 until 1.4.19, the file upload processing system contains an SSRF vulnerability that allows unauthenticated remote attackers to force the server to make… | ||
| CVE-2025-52362 | Cri | 0.59 | 9.1 | 0.00 | Jul 21, 2025 | Server-Side Request Forgery (SSRF) vulnerability exists in the URL processing functionality of PHProxy version 1.1.1 and prior. The input validation for the _proxurl parameter can be bypassed, allowing a remote, unauthenticated attacker to submit a specially crafted URL | ||
| CVE-2025-4967 | Cri | 0.59 | 9.1 | 0.00 | May 29, 2025 | Esri Portal for ArcGIS 11.4 and prior allows a remote, unauthenticated attacker to bypass the Portal’s SSRF protections. | ||
| CVE-2024-6584 | Cri | 0.59 | 9.1 | 0.01 | May 15, 2025 | The 'wp_ajax_boost_proxy_ig' action allows administrators to make GET requests to arbitrary URLs. | ||
| CVE-2025-45887 | Cri | 0.59 | 9.1 | 0.00 | May 9, 2025 | Yifang CMS v2.0.2 is vulnerable to Server-Side Request Forgery (SSRF) in /api/file/getRemoteContent. | ||
| CVE-2025-47733 | Cri | 0.59 | 9.1 | 0.02 | May 8, 2025 | Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network | ||
| CVE-2025-28197 | Cri | 0.59 | 9.1 | 0.00 | Apr 18, 2025 | Crawl4AI <=0.4.247 is vulnerable to SSRF in /crawl4ai/async_dispatcher.py. | ||
| CVE-2025-28091 | Cri | 0.59 | 9.1 | 0.00 | Mar 28, 2025 | maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article. | ||
| CVE-2025-28090 | Cri | 0.59 | 9.1 | 0.00 | Mar 28, 2025 | maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature. |
- risk 0.59cvss 9.1epss 0.00
Chamilo is a learning management system. Prior to version 1.11.30, there is a blind SSRF vulnerability in /index.php via the POST openid_url parameter. This issue has been patched in version 1.11.30.
- risk 0.59cvss 9.1epss 0.00
SoftVision webPDF before 10.0.2 is vulnerable to Server-Side Request Forgery (SSRF). The PDF converter function does not check if internal or external resources are requested in the uploaded files and allows for protocols such as http:// and file:///. This allows an attacker to…
- risk 0.59cvss 9.1epss 0.00
Squidex is an open source headless content management system and content management hub. Versions of the application up to and including 7.21.0 allow users to define "Webhooks" as actions within the Rules engine. The url parameter in the webhook configuration does not appear to…
- risk 0.59cvss 9.1epss 0.00
A critical vulnerability has been identified in givanz VvvebJs 1.7.2, which allows both Server-Side Request Forgery (SSRF) and arbitrary file reading. The vulnerability stems from improper handling of user-supplied URLs in the "file_get_contents" function within the "save.php"…
- risk 0.59cvss 9.1epss 0.00
In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig and the configuration allows undefined PHP functions to be registered
- risk 0.59cvss 9.1epss 0.00
Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on Web-based platforms allows an attacker to force the server to perform HTTP GET requests via crafted import requests to an arbitrary destination.
- risk 0.59cvss 9.1epss 0.00
PublicCMS V5.202506.b is vulnerable to SSRF. in the chat interface of SimpleAiAdminController.
- risk 0.59cvss 9.1epss 0.01
Accela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script feature. An authenticated administrative user can execute arbitrary Java code on the server, resulting in remote code execution. In addition, improper input validation allows for…
- risk 0.59cvss 9.1epss 0.00
halo v2.20.17 and before is vulnerable to server-side request forgery (SSRF) in /apis/uc.api.storage.halo.run/v1alpha1/attachments/-/upload-from-url.
- risk 0.59cvss 9.1epss 0.00
A Server-Side Request Forgery (SSRF) in the UISP Application may allow a malicious actor with certain permissions to make requests outside of UISP Application scope.
- risk 0.59cvss 9.1epss 0.00
Server side request forgery (SSRF) vulnerability in makeplane plane 0.23.1 via the password recovery.
- risk 0.59cvss 9.9epss 0.15
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1.4.0 until 1.4.19, the file upload processing system contains an SSRF vulnerability that allows unauthenticated remote attackers to force the server to make…
- risk 0.59cvss 9.1epss 0.00
Server-Side Request Forgery (SSRF) vulnerability exists in the URL processing functionality of PHProxy version 1.1.1 and prior. The input validation for the _proxurl parameter can be bypassed, allowing a remote, unauthenticated attacker to submit a specially crafted URL
- risk 0.59cvss 9.1epss 0.00
Esri Portal for ArcGIS 11.4 and prior allows a remote, unauthenticated attacker to bypass the Portal’s SSRF protections.
- risk 0.59cvss 9.1epss 0.01
The 'wp_ajax_boost_proxy_ig' action allows administrators to make GET requests to arbitrary URLs.
- risk 0.59cvss 9.1epss 0.00
Yifang CMS v2.0.2 is vulnerable to Server-Side Request Forgery (SSRF) in /api/file/getRemoteContent.
- risk 0.59cvss 9.1epss 0.02
Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network
- risk 0.59cvss 9.1epss 0.00
Crawl4AI <=0.4.247 is vulnerable to SSRF in /crawl4ai/async_dispatcher.py.
- risk 0.59cvss 9.1epss 0.00
maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article.
- risk 0.59cvss 9.1epss 0.00
maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature.