VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,621)

page 26 of 182
  • CVE-2025-5260HigAug 20, 2025
    risk 0.56cvss 8.6epss 0.00

    Server-Side Request Forgery (SSRF) vulnerability in Pik Online Yazılım Çözümleri A.Ş. Pik Online allows Server Side Request Forgery. This issue affects Pik Online: before 3.1.5.

  • CVE-2025-25235HigAug 11, 2025
    risk 0.56cvss 8.6epss 0.00

    Server-Side Request Forgery (SSRF) in Omnissa Secure Email Gateway (SEG) in SEG prior to 2.32 running on Windows and SEG prior to 2503 running on UAG allows routing of network traffic such as HTTP requests to internal networks.

  • CVE-2025-4581HigAug 9, 2025
    risk 0.56cvss 8.6epss 0.00

    Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4 ,2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15, 7.4 GA through update 92 allows a pre-authentication blind SSRF…

  • CVE-2025-36845HigJul 21, 2025
    risk 0.56cvss 8.6epss 0.02

    An issue was discovered in Eveo URVE Web Manager 27.02.2025. The endpoint /_internal/redirect.php allows for Server-Side Request Forgery (SSRF). The endpoint takes a URL as input, sends a request to this address, and reflects the content in the response. This can be used to…

  • CVE-2025-46385HigJul 20, 2025
    risk 0.56cvss 8.6epss 0.00

    CWE-918 Server-Side Request Forgery (SSRF)

  • CVE-2025-36560HigMay 19, 2025
    risk 0.56cvss 8.6epss 0.01

    Server-side request forgery vulnerability exists in a-blog cms multiple versions. If this vulnerability is exploited, a remote unauthenticated attacker may gain access to sensitive information by sending a specially crafted request.

  • CVE-2025-27501HigMar 3, 2025
    risk 0.56cvss 8.6epss 0.00

    OpenZiti is a free and open source project focused on bringing zero trust to any application. An endpoint on the admin panel can be accessed without any form of authentication. This endpoint accepts a user-supplied URL parameter to connect to an OpenZiti Controller and performs…

  • CVE-2024-37359HigFeb 19, 2025
    risk 0.56cvss 8.6epss 0.01

    The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination. (CWE-918)   Hitachi Vantara Pentaho Business Analytics…

  • CVE-2023-50733HigJan 21, 2025
    risk 0.56cvss 8.6epss 0.00

    A Server-Side Request Forgery (SSRF) vulnerability has been identified in the Web Services feature of newer Lexmark devices.

  • CVE-2024-57767HigJan 15, 2025
    risk 0.56cvss 8.6epss 0.00

    MSFM before v2025.01.01 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /file/download.

  • CVE-2021-38135HigNov 22, 2024
    risk 0.56cvss 8.6epss 0.00

    Possible External Service Interaction attack in iManager has been discovered in OpenText™ iManager 3.2.6.0000.

  • CVE-2024-38206HigAug 6, 2024
    risk 0.56cvss 8.5epss 0.12

    An authenticated attacker can bypass Server-Side Request Forgery (SSRF) protection in Microsoft Copilot Studio to leak sensitive information over a network.

  • CVE-2024-5885HigJun 27, 2024
    risk 0.56cvss 8.6epss 0.01

    stangirard/quivr version 0.0.236 contains a Server-Side Request Forgery (SSRF) vulnerability. The application does not provide sufficient controls when crawling a website, allowing an attacker to access applications on the local network. This vulnerability could allow a…

  • CVE-2024-37818HigJun 20, 2024
    risk 0.56cvss 8.6epss 0.01

    Strapi v4.24.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /strapi.io/_next/image. This vulnerability allows attackers to scan for open ports or access sensitive information via a crafted GET request. NOTE: The Strapi Development Community…

  • CVE-2024-32964CriMay 14, 2024
    risk 0.56cvss 9.0epss 0.53

    Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. Prior to 0.150.6, lobe-chat had an unauthorized Server-Side Request Forgery vulnerability in the /api/proxy endpoint. An attacker can construct malicious…

  • CVE-2024-25187HigApr 2, 2024
    risk 0.56cvss 8.6epss 0.01

    Server Side Request Forgery (SSRF) vulnerability in 71cms v1.0.0, allows remote unauthenticated attackers to obtain sensitive information via getweather.html.

  • CVE-2023-28288HigApr 11, 2023
    risk 0.56cvss 8.1epss 0.06

    Microsoft SharePoint Server Spoofing Vulnerability

  • CVE-2022-41412HigNov 30, 2022
    risk 0.56cvss 8.6epss 0.04

    An issue in the graphData.cgi component of perfSONAR v4.4.5 and prior allows attackers to access sensitive data and execute Server-Side Request Forgery (SSRF) attacks.

  • CVE-2022-31188HigAug 1, 2022
    risk 0.56cvss 8.6epss 0.49

    CVAT is an opensource interactive video and image annotation tool for computer vision. Versions prior to 2.0.0 were found to be subject to a Server-side request forgery (SSRF) vulnerability. Validation has been added to urls used in the affected code path in version 2.0.0. Users…

  • CVE-2022-29847HigMay 11, 2022
    risk 0.56cvss 7.5epss 0.58

    In Progress Ipswitch WhatsUp Gold 21.0.0 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to invoke an API transaction that would allow them to relay encrypted WhatsUp Gold user credentials to an arbitrary host.