VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,225)

page 3 of 162
  • CVE-2026-32169CriMar 19, 2026
    risk 0.65cvss 10.0epss 0.01

    Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2025-64180CriNov 7, 2025
    risk 0.65cvss 10.0epss 0.00

    Manager-io/Manager is accounting software. In Manager Desktop and Server versions 25.11.1.3085 and below, a critical vulnerability permits unauthorized access to internal network resources. The flaw lies in the fundamental design of the DNS validation mechanism. A Time-of-Check…

  • CVE-2025-59503CriOct 23, 2025
    risk 0.65cvss 10.0epss 0.01

    Server-side request forgery (ssrf) in Azure Compute Gallery allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2025-53767CriAug 7, 2025
    risk 0.65cvss 10.0epss 0.01

    Azure OpenAI Elevation of Privilege Vulnerability

  • CVE-2025-29972CriMay 8, 2025
    risk 0.65cvss 9.9epss 0.03

    Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network.

  • CVE-2023-39967CriSep 6, 2023
    risk 0.65cvss 10.0epss 0.01

    WireMock is a tool for mocking HTTP services. When certain request URLs like “@127.0.0.1:1234" are used in WireMock Studio configuration fields, the request might be forwarded to an arbitrary service reachable from WireMock’s instance. There are 3 identified potential attack…

  • CVE-2023-23560CriJan 23, 2023
    risk 0.65cvss 9.8epss 0.14

    In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation.

  • CVE-2022-32995CriJun 27, 2022
    risk 0.65cvss 9.8epss 0.16

    Halo CMS v1.5.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the template remote download function.

  • CVE-2021-41403CriJun 15, 2022
    risk 0.65cvss 9.8epss 0.19

    flatCore-CMS version 2.0.8 calls dangerous functions, causing server-side request forgery vulnerabilities.

  • CVE-2022-21215CriFeb 18, 2022
    risk 0.65cvss 10.0epss 0.01

    This vulnerability could allow an attacker to force the server to create and execute a web request granting access to backend APIs that are only accessible to the Mimosa MMP server, or request pages that could perform some actions themselves. The attacker could force the server…

  • CVE-2021-32682CriJun 14, 2021
    risk 0.65cvss 9.8epss 0.70

    elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerabilities can allow an attacker to execute arbitrary code and commands on the server hosting the elFinder PHP connector, even with…

  • CVE-2021-27329CriFeb 18, 2021
    risk 0.65cvss 10.0epss 0.02

    Friendica 2021.01 allows SSRF via parse_url?binurl= for DNS lookups or HTTP requests to arbitrary domain names.

  • CVE-2020-8540CriMar 11, 2020
    risk 0.65cvss 9.8epss 0.13

    An XML external entity (XXE) vulnerability in Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.

  • CVE-2019-13020CriAug 26, 2019
    risk 0.65cvss 10.0epss 0.01

    The fetch API in Tightrope Media Carousel before 7.1.3 has CarouselAPI/v0/fetch?url= SSRF. This has two potential areas for abuse. First, a specially crafted URL could be used in a phishing attack to hijack the trust the user and the browser have with the website and could serve…

  • CVE-2016-10927CriAug 22, 2019
    risk 0.65cvss 10.0epss 0.02

    The nelio-ab-testing plugin before 4.5.11 for WordPress has SSRF in ajax/iesupport.php.

  • CVE-2016-10926CriAug 22, 2019
    risk 0.65cvss 10.0epss 0.02

    The nelio-ab-testing plugin before 4.5.9 for WordPress has SSRF in ajax/iesupport.php.

  • CVE-2019-12153CriJun 11, 2019
    risk 0.65cvss 10.0epss 0.02

    Lack of validation in the HTML parser in RealObjects PDFreactor before 10.1.10722 leads to SSRF, allowing attackers to access network or file resources on behalf of the server by supplying malicious HTML content.

  • CVE-2019-9174CriApr 17, 2019
    risk 0.65cvss 10.0epss 0.02

    An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows SSRF.

  • CVE-2019-10686CriApr 1, 2019
    risk 0.65cvss 10.0epss 0.02

    An SSRF vulnerability was found in an API from Ctrip Apollo through 1.4.0-SNAPSHOT. An attacker may use it to do an intranet port scan or raise a GET request via /system-info/health because the %23 substring is mishandled.

  • CVE-2019-3905CriJan 3, 2019
    risk 0.65cvss 10.0epss 0.03

    Zoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF.