VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,682)

page 85 of 185
  • CVE-2025-6729MedJul 4, 2025
    risk 0.42cvss 6.4epss 0.00

    The PayMaster for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 0.4.31 via the 'wp_ajax_paym_status' AJAX action This makes it possible for authenticated attackers, with Subscriber-level access and above, to…

  • CVE-2025-52713MedJun 20, 2025
    risk 0.42cvss 6.4epss 0.00

    Server-Side Request Forgery (SSRF) vulnerability in BoldGrid Post and Page Builder by BoldGrid post-and-page-builder allows Server Side Request Forgery.This issue affects Post and Page Builder by BoldGrid: from n/a through <= 1.27.8.

  • CVE-2025-30679MedJun 17, 2025
    risk 0.42cvss 6.5epss 0.00

    A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (on-premise) modOSCE component could allow an attacker to manipulate certain parameters leading to information disclosure on affected installations.

  • CVE-2025-30678MedJun 17, 2025
    risk 0.42cvss 6.5epss 0.00

    A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (on-premise) modTMSM component could allow an attacker to manipulate certain parameters leading to information disclosure on affected installations.

  • CVE-2024-7073MedJun 2, 2025
    risk 0.42cvss 6.5epss 0.00

    A server-side request forgery (SSRF) vulnerability exists in multiple WSO2 products due to improper input validation in SOAP admin services. This flaw allows unauthenticated attackers to manipulate server-side requests, enabling access to internal and external resources…

  • CVE-2025-47484MedMay 7, 2025
    risk 0.42cvss 6.4epss 0.00

    Server-Side Request Forgery (SSRF) vulnerability in Oliver Campion Display Remote Posts Block display-remote-posts-block allows Server Side Request Forgery.This issue affects Display Remote Posts Block: from n/a through <= 1.1.0.

  • CVE-2024-55910MedMay 2, 2025
    risk 0.42cvss 6.5epss 0.00

    IBM Concert Software 1.0.0 through 1.0.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

  • CVE-2025-3775MedApr 25, 2025
    risk 0.42cvss 6.5epss 0.00

    The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.2 via the woolentor_template_proxy function. This…

  • CVE-2025-46511MedApr 24, 2025
    risk 0.42cvss 6.4epss 0.00

    Server-Side Request Forgery (SSRF) vulnerability in Derek Springer BeerXML Shortcode beerxml-shortcode allows Server Side Request Forgery.This issue affects BeerXML Shortcode: from n/a through <= 0.7.1.

  • CVE-2025-29456MedApr 17, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the create Notes function.

  • CVE-2025-29453MedApr 17, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the my-contacts-settings component.

  • CVE-2025-29455MedApr 17, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Travel Ideas" function.

  • CVE-2025-29454MedApr 17, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Upload function.

  • CVE-2025-29450MedApr 17, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the site settings component.

  • CVE-2025-29449MedApr 17, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the link identification function.

  • CVE-2025-31527MedMar 31, 2025
    risk 0.42cvss 6.4epss 0.00

    Server-Side Request Forgery (SSRF) vulnerability in Kishan WP Link Preview wp-link-preview allows Server Side Request Forgery.This issue affects WP Link Preview: from n/a through <= 1.4.1.

  • CVE-2025-28094MedMar 28, 2025
    risk 0.42cvss 6.5epss 0.00

    shopxo v6.4.0 has a ssrf/xss vulnerability in multiple places.

  • CVE-2025-27406HigMar 26, 2025
    risk 0.42cvss 7.6epss 0.00

    Icinga Reporting is the central component for reporting related functionality in the monitoring web frontend and framework Icinga Web 2. A vulnerability present in versions 0.10.0 through 1.0.2 allows to set up a template that allows to embed arbitrary Javascript. This enables…

  • CVE-2025-1912HigMar 26, 2025
    risk 0.42cvss 7.6epss 0.00

    The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.0 via the validate_file() Function. This makes it possible for authenticated attackers, with…

  • CVE-2025-1970HigMar 22, 2025
    risk 0.42cvss 7.6epss 0.00

    The Export and Import Users and Customers plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6.2 via the validate_file() function. This makes it possible for authenticated attackers, with Administrator-level access and…