VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,680)

page 166 of 184
  • CVE-2022-0249LowMar 28, 2022
    risk 0.20cvss 3.1epss 0.01

    A vulnerability was discovered in GitLab starting with version 12. GitLab was vulnerable to a blind SSRF attack since requests to shared address space were not blocked.

  • CVE-2016-6001LowFeb 1, 2017
    risk 0.20cvss 3.1epss 0.01

    IBM Forms Experience Builder could be susceptible to a server-side request forgery (SSRF) from the application design interface allowing for some information disclosure of internal resources.

  • CVE-2026-19504MedSep 15, 2026
    risk 0.19cvss 4.0epss 0.00

    Fabric.js loadFromJSON Server-Side Request Forgery Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Fabric.js. Interaction with this library is required to exploit this vulnerability but attack vectors may…

  • CVE-2026-53945MedJun 24, 2026
    risk 0.19cvss 4.0epss 0.00

    Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, Ghost’s private-IP check for outbound HTTP requests could be bypassed via DNS rebinding, allowing an attacker to coerce the Ghost server into reaching hosts on internal networks through features that issue…

  • CVE-2026-44430MedMay 14, 2026
    risk 0.19cvss 4.0epss 0.00

    The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.7, the Registry's HTTP-based namespace verification (POST /v0/auth/http, POST /v0.1/auth/http) uses safeDialContext (internal/api/handlers/v0/auth/http.go:67-110) to…

  • CVE-2026-31804MedMar 30, 2026
    risk 0.19cvss 4.0epss 0.00

    Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /pms_image_proxy endpoint accepts a user-supplied img parameter and forwards it to Plex Media Server's /photo/:/ transcode transcoder without authentication and without…

  • CVE-2026-13176LowAug 21, 2026
    risk 0.18cvss 2.7epss 0.00

    The Eventin WordPress plugin before 4.1.21 does not validate a user-supplied webhook URL stored on events nor verify event ownership, allowing users with contributor-level access and above to trigger blind server-side requests to arbitrary hosts.

  • CVE-2026-76361LowAug 19, 2026
    risk 0.18cvss 2.7epss 0.00

    In Splunk SOAR versions below 8.6.0, a user with the "Administrator" role could use the /rest/support/connectivity/.../check_connectivity endpoint to make Splunk SOAR initiate outbound network connections to arbitrary destinations and determine whether internal hosts and ports…

  • CVE-2026-17597LowAug 7, 2026
    risk 0.18cvss 2.7epss 0.00

    Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability in the email configuration verification feature. A user holding the nexus:settings:update permission could submit arbitrary host and port values to the email test/verification endpoint, causing the…

  • CVE-2025-20388LowDec 3, 2025
    risk 0.18cvss 2.7epss 0.00

    In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.4, 10.0.2503.7, and 9.3.2411.116, a user who holds a role that contains the high privilege capability `change_authentication` could enumerate internal IP…

  • CVE-2025-54234LowAug 18, 2025
    risk 0.18cvss 2.7epss 0.01

    ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to limited file system read. A high-privilege authenticated attacker can force the application to make arbitrary requests via injection of…

  • CVE-2025-8013LowAug 15, 2025
    risk 0.18cvss 3.8epss 0.00

    The Quttera Web Malware Scanner plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.5.1.41 via the 'RunExternalScan' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to…

  • CVE-2025-4012LowApr 28, 2025
    risk 0.18cvss 2.7epss 0.00

    A vulnerability was found in playeduxyz PlayEdu 开源培训系统 up to 1.8 and classified as problematic. This issue affects some unknown processing of the file /api/backend/v1/user/create of the component User Avatar Handler. The manipulation of the argument Avatar leads to…

  • CVE-2025-3787LowApr 18, 2025
    risk 0.18cvss 2.7epss 0.00

    A vulnerability was found in PbootCMS 3.2.5. It has been classified as problematic. Affected is an unknown function of the component Image Handler. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed…

  • CVE-2025-3691LowApr 16, 2025
    risk 0.18cvss 2.7epss 0.01

    A vulnerability was found in mirweiye Seven Bears Library CMS 2023. It has been classified as problematic. Affected is an unknown function of the component Add Link Handler. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The…

  • CVE-2024-13032LowDec 30, 2024
    risk 0.18cvss 2.7epss 0.01

    A vulnerability classified as problematic was found in Antabot White-Jotter up to 0.2.2. Affected by this vulnerability is an unknown functionality of the file /admin/content/editor of the component Article Editor. The manipulation of the argument articleCover leads to…

  • CVE-2024-47190LowNov 8, 2024
    risk 0.18cvss 2.7epss 0.00

    Northern.tech Hosted Mender before 2024.07.11 allows SSRF.

  • CVE-2022-2556LowAug 29, 2022
    risk 0.18cvss 2.7epss 0.01

    The Mailchimp for WooCommerce WordPress plugin before 2.7.2 has an AJAX action that allows high privilege users to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it can be used to scan…

  • CVE-2021-25939LowFeb 9, 2022
    risk 0.18cvss 2.7epss 0.01

    In ArangoDB, versions v3.7.0 through v3.9.0-alpha.1 have a feature which allows downloading a Foxx service from a publicly available URL. This feature does not enforce proper filtering of requests performed internally, which can be abused by a highly-privileged attacker to…

  • CVE-2021-22033LowOct 13, 2021
    risk 0.18cvss 2.7epss 0.01

    Releases prior to VMware vRealize Operations 8.6 contain a Server Side Request Forgery (SSRF) vulnerability.