VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,621)

page 30 of 182
  • CVE-2026-42313HigMay 11, 2026
    risk 0.54cvss 8.3epss 0.00

    pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SETTINGS)) in src/pyload/core/api/__init__.py gates security-sensitive options behind a hand-maintained allowlist…

  • CVE-2026-41271HigApr 23, 2026
    risk 0.54cvss 8.3epss 0.00

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side Request Forgery (SSRF) vulnerability exists in FlowiseAI's POST/GET API Chain components that allows unauthenticated attackers to force the server to make…

  • CVE-2026-1313HigMar 21, 2026
    risk 0.54cvss 8.3epss 0.00

    The MimeTypes Link Icons plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.2.20. This is due to the plugin making outbound HTTP requests to user-controlled URLs without proper validation when the "Show file size" option is…

  • CVE-2025-21384HigApr 1, 2025
    risk 0.54cvss 8.3epss 0.01

    An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network.

  • CVE-2024-8099HigMar 20, 2025
    risk 0.54cvss 8.3epss 0.00

    A Server-Side Request Forgery (SSRF) vulnerability exists in the latest version of vanna-ai/vanna when using DuckDB as the database. An attacker can exploit this vulnerability by submitting crafted SQL queries that leverage DuckDB's default features, such as `read_csv`,…

  • CVE-2024-54819CriJan 7, 2025
    risk 0.54cvss 9.1epss 0.18

    I, Librarian before and including 5.11.1 is vulnerable to Server-Side Request Forgery (SSRF) due to improper input validation in classes/security/validation.php

  • CVE-2012-10018HigOct 16, 2024
    risk 0.54cvss 8.3epss 0.01

    The Mapplic and Mapplic Lite plugins for WordPress are vulnerable to Server-Side Request Forgery in versions up to, and including 6.1, 1.0 respectively. This makes it possible for attackers to forgery requests coming from a vulnerable site's server and ultimately perform an XSS…

  • CVE-2024-24759CriSep 5, 2024
    risk 0.54cvss 9.3epss 0.05

    MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat actor can bypass the server-side request forgery protection on the whole website with DNS Rebinding. The vulnerability can also lead to denial of service.…

  • CVE-2024-2663HigApr 30, 2024
    risk 0.54cvss 8.3epss 0.00

    The ZD YouTube FLV Player plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.2.6 via the $_GET['image'] parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating…

  • CVE-2024-28752CriMar 15, 2024
    risk 0.54cvss 9.3epss 0.02

    A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (including the default databinding)…

  • CVE-2023-50968HigDec 26, 2023
    risk 0.54cvss 7.5epss 0.63

    Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations. The same uri can be operated to realize a SSRF attack also without authorizations. Users are recommended to upgrade to version…

  • CVE-2023-46729CriNov 10, 2023
    risk 0.54cvss 9.3epss 0.01

    sentry-javascript provides Sentry SDKs for JavaScript. An unsanitized input of Next.js SDK tunnel endpoint allows sending HTTP requests to arbitrary URLs and reflecting the response back to the user. This issue only affects users who have Next.js SDK tunneling feature enabled.…

  • CVE-2023-46229HigOct 19, 2023
    risk 0.54cvss 8.8epss 0.45

    LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an internal server.

  • CVE-2023-41763MedKEVOct 10, 2023
    risk 0.54cvss 5.3epss 0.90

    Skype for Business Elevation of Privilege Vulnerability

  • CVE-2022-20958HigNov 4, 2022
    risk 0.54cvss 8.3epss 0.01

    A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot application could allow an unauthenticated, remote attacker to perform a server-side request forgery (SSRF) attack on an affected device. This vulnerability is due to insufficient validation…

  • CVE-2022-31132HigAug 4, 2022
    risk 0.54cvss 8.3epss 0.01

    Nextcloud Mail is an email application for the nextcloud personal cloud product. Affected versions shipped with a CSS minifier on the path `./vendor/cerdic/css-tidy/css_optimiser.php`. Access to the minifier is unrestricted and access may lead to Server-Side Request Forgery…

  • CVE-2022-24129HigFeb 4, 2022
    risk 0.54cvss 8.2epss 0.06

    The OIDC OP plugin before 3.0.4 for Shibboleth Identity Provider allows server-side request forgery (SSRF) due to insufficient restriction of the request_uri parameter. This allows attackers to interact with arbitrary third-party HTTP services.

  • CVE-2020-24140HigApr 7, 2021
    risk 0.54cvss 8.3epss 0.01

    Server-side request forgery in Wcms 0.3.2 let an attacker send crafted requests from the back-end server of a vulnerable web application via the pagename parameter to wex/html.php. It can help identify open ports, local network hosts and execute command on local services.

  • CVE-2020-24139HigApr 7, 2021
    risk 0.54cvss 8.3epss 0.01

    Server-side request forgery in Wcms 0.3.2 lets an attacker send crafted requests from the back-end server of a vulnerable web application via the path parameter to wex/cssjs.php. It can help identify open ports, local network hosts and execute command on local services.

  • CVE-2020-10252HigFeb 19, 2021
    risk 0.54cvss 8.3epss 0.01

    An issue was discovered in ownCloud before 10.4. Because of an SSRF issue (via the apps/files_sharing/external remote parameter), an authenticated attacker can interact with local services blindly (aka Blind SSRF) or conduct a Denial Of Service attack.