← Back
CWE-918

3,450 CVEs • Abstraction: Base

Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

JSON object

Loading...

CVEs (3,450)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Personal Management System
1Personal Management System
Jun 17, 2026
Apr 17, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the my-contacts-settings component.
1Personal Management System
1Personal Management System
Jun 17, 2026
Apr 17, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Travel Ideas" function.
1Personal Management System
1Personal Management System
Jun 17, 2026
Apr 17, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Upload function.
1Seopanel
1Seo Panel
Jun 17, 2026
Apr 17, 2025
N/A· v4
7.6 HIGH· v3
N/A· v2
An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Proxy Manager component.
1Seopanel
1Seo Panel
Jun 17, 2026
Apr 17, 2025
N/A· v4
7.6 HIGH· v3
N/A· v2
An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Mail Setting component.
1Lm21
1Twonav
Jun 17, 2026
Apr 17, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the site settings component.
1Lm21
1Twonav
Jun 17, 2026
Apr 17, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the link identification function.
1Apache
1Hertzbeat
Jun 17, 2026
Apr 16, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Server-Side Request Forgery (SSRF) vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat (incubating): before 1.7.0. Users are recommended to upgrade to version 1.7.0, which fixes the issue.
1Mirweiye
1Seven Bears Library Cms
Jun 17, 2026
Apr 16, 2025
5.1 MEDIUM· v4
5.3 MEDIUM· v3
3.3 LOW· v2
A vulnerability was found in mirweiye Seven Bears Library CMS 2023. It has been classified as problematic. Affected is an unknown function of the component Add Link Handler. The manipulation leads to server-side request...Show more
A vulnerability was found in mirweiye Seven Bears Library CMS 2023. It has been classified as problematic. Affected is an unknown function of the component Add Link Handler. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.Show less
1Crushftp
1Crushftp
Jun 17, 2026
Apr 15, 2025
N/A· v4
5.0 MEDIUM· v3
N/A· v2
CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows SSRF via the host and port parameters in a command=telnetSocket request to the /WebInterface/function/ URI.
-
-
Jun 17, 2026
Apr 15, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Server-Side Request Forgery (SSRF) vulnerability in ThemeGoods Photography photography allows Server Side Request Forgery.This issue affects Photography: from n/a through < 7.7.6.
1Royal Elementor Addons
1Royal Elementor Addons
Jun 17, 2026
Apr 15, 2025
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Server-Side Request Forgery (SSRF) vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Server Side Request Forgery.This issue affects Royal Elementor Addons: from n/a through <= 1.7.1006.
1Agpt
1Autogpt Platform
Jun 17, 2026
Apr 14, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to 0.6.1, AutoGPT allows SSRF due to DNS Rebinding in requests wrappe...Show more
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to 0.6.1, AutoGPT allows SSRF due to DNS Rebinding in requests wrapper. AutoGPT is built with a wrapper around Python's requests library, hardening the application against SSRF. The code for this wrapper can be found in autogpt_platform/backend/backend/util/request.py. The requested hostname of a URL which is being requested is validated, ensuring that it does not resolve to any local ipv4 or ipv6 addresses. However, this check is not sufficient, as a DNS server may initially respond with a non-blocked address, with a TTL of 0. This means that the initial resolution would appear as a non-blocked address. In this case, validate_url() will return the url as successful. After validate_url() has successfully returned the url, the url is then passed to the real request() function. When the real request() function is called with the validated url, request() will once again resolve the address of the hostname, because the record will not have been cached (due to TTL 0). This resolution may be in the "invalid range". This type of attack is called a "DNS Rebinding Attack". This vulnerability is fixed in 0.6.1.Show less
1Langgenius
1Dify
Jun 17, 2026
Apr 14, 2025
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Dify v1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi.
1Intumit
2Smartrobot
Smartrobot Firmware
Jun 17, 2026
Apr 14, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
SmartRobot from INTUMIT has a Server-Side Request Forgery vulnerability, allowing unauthenticated remote attackers to probe internal network and even access arbitrary local files on the server.
-
-
Jun 17, 2026
Apr 10, 2025
6.0 MEDIUM· v4
N/A· v3
N/A· v2
A Server-Side Request Forgery (SSRF) vulnerability was discovered in the videx-legacy-ssl web service of Videx’s CyberAudit-Web, affecting versions prior to 1.1.3. This vulnerability has been patched in versions after 1....Show more
A Server-Side Request Forgery (SSRF) vulnerability was discovered in the videx-legacy-ssl web service of Videx’s CyberAudit-Web, affecting versions prior to 1.1.3. This vulnerability has been patched in versions after 1.1.3. Leaving this vulnerability unpatched could lead to unauthorized access to the underlying infrastructure.Show less
1Octopus
1Octopus Server
Jun 17, 2026
Apr 10, 2025
5.9 MEDIUM· v4
8.8 HIGH· v3
N/A· v2
In affected Microsoft Windows versions of Octopus Deploy, the server can be coerced into sending server-side requests that contain authentication material allowing a suitably positioned attacker to compromise the account...Show more
In affected Microsoft Windows versions of Octopus Deploy, the server can be coerced into sending server-side requests that contain authentication material allowing a suitably positioned attacker to compromise the account running Octopus Server and potentially the host infrastructure itself.Show less
-
-
Jun 17, 2026
Apr 9, 2025
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Server-Side Request Forgery (SSRF) vulnerability in blubrry PowerPress Podcasting powerpress allows Server Side Request Forgery.This issue affects PowerPress Podcasting: from n/a through <= 11.12.6.
-
-
Jun 17, 2026
Apr 9, 2025
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Server-Side Request Forgery (SSRF) vulnerability in QuantumCloud SEO Help seo-help allows Server Side Request Forgery.This issue affects SEO Help: from n/a through <= 6.7.9.
-
-
Jun 17, 2026
Apr 9, 2025
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Server-Side Request Forgery (SSRF) vulnerability in Joe Waymark waymark allows Server Side Request Forgery.This issue affects Waymark: from n/a through <= 1.5.2.