VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,679)

page 2 of 184
  • CVE-2020-35313CriApr 20, 2021
    risk 0.70cvss 9.8epss 0.45

    A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remote attackers to execute arbitrary code via a crafted URL to the theme/plugin installer.

  • CVE-2022-1386CriMay 16, 2022
    risk 0.69cvss 9.8epss 0.71

    The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms which could be used to initiate arbitrary HTTP requests. The data returned is then reflected back in the application's response. This could be used to interact…

  • CVE-2021-22054HigKEVDec 17, 2021
    risk 0.69cvss 7.5epss 1.00

    VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without…

  • CVE-2021-27670CriFeb 25, 2021
    risk 0.69cvss 9.8epss 0.61

    Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.

  • CVE-2022-35583CriAug 22, 2022
    risk 0.68cvss 9.8epss 0.15

    wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial asset IP address on it's source. This allows the attacker to takeover the whole infrastructure by accessing their internal assets.

  • CVE-2021-24472CriAug 2, 2021
    risk 0.68cvss 9.8epss 0.57

    The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functionality to unauthenticated users, sending requests to this proxy functionality will have the web server fetch and display the content from any URI, this would…

  • CVE-2019-16932CriSep 30, 2019
    risk 0.68cvss 10.0epss 0.39

    A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.

  • CVE-2019-8982CriFeb 21, 2019
    risk 0.68cvss 9.6epss 0.28

    com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&inUrl= value, leading to disclosure of local files and SSRF.

  • CVE-2018-11586CriJun 5, 2018
    risk 0.68cvss 9.8epss 0.15

    XML external entity (XXE) vulnerability in api/rest/status in SearchBlox 8.6.7 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.

  • CVE-2002-1484CriApr 22, 2003
    risk 0.68cvss 9.8epss 0.14

    DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other systems (port scan) via a request for a URL that specifies the target IP address and port, which produces a connection status in…

  • CVE-2013-4864CriJan 28, 2020
    risk 0.67cvss 9.8epss 0.06

    MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url parameter to cgi-bin/cmh/proxy.sh, related to a Server-Side Request Forgery (SSRF) issue.

  • CVE-2004-2061CriJul 27, 2004
    risk 0.67cvss 9.8epss 0.06

    RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) http://, (2) ftp://, or (3) file:// URL.

  • CVE-2026-64849CriKEVAug 17, 2026
    risk 0.66cvss 9.3epss 0.10

    MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the…

  • CVE-2023-49785CriMar 12, 2024
    risk 0.66cvss 9.1epss 0.83

    NextChat, also known as ChatGPT-Next-Web, is a cross-platform chat user interface for use with ChatGPT. Versions 2.11.2 and prior are vulnerable to server-side request forgery and cross-site scripting. This vulnerability enables read access to internal HTTP endpoints but also…

  • CVE-2023-48022CriNov 28, 2023
    risk 0.66cvss 9.8epss 0.84

    Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its documentation, is not intended for use outside of a strictly controlled network…

  • CVE-2019-9827CriJul 3, 2019
    risk 0.66cvss 9.8epss 0.27

    Hawt Hawtio through 2.5.0 is vulnerable to SSRF, allowing a remote attacker to trigger an HTTP request from an affected server to an arbitrary host via the initial /proxy/ substring of a URI.

  • CVE-2018-12571CriJul 5, 2018
    risk 0.66cvss 9.8epss 0.30

    uniquesig0/InternalSite/InitParams.aspx in Microsoft Forefront Unified Access Gateway 2010 allows remote attackers to trigger outbound DNS queries for arbitrary hosts via a comma-separated list of URLs in the orig_url parameter, possibly causing a traffic amplification and/or…

  • CVE-2026-92808CriSep 16, 2026
    risk 0.65cvss —epss 0.01

    A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An unauthenticated network attacker can cause the server to issue outbound HTTP requests to a destination of the attacker's choosing, including internal services…

  • CVE-2026-75754CriSep 4, 2026
    risk 0.65cvss —epss 0.00

    Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized user to obtain the encryption key via an HTTP request, causing a local service to enable SSH on port 2222. The…

  • CVE-2026-76193CriAug 25, 2026
    risk 0.65cvss 10.0epss 0.01

    Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue…