← Back
CWE-918

3,430 CVEs • Abstraction: Base

Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

JSON object

Loading...

CVEs (3,430)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Khoros
1Lithium Forum
Nov 21, 2024
Jun 28, 2022
N/A· v4
4.4 MEDIUM· v3
3.6 LOW· v2
A vulnerability, which was classified as critical, has been found in Lithium Forum 2017 Q1. This issue affects some unknown processing of the component Compose Message Handler. The manipulation of the argument upload_url...Show more
A vulnerability, which was classified as critical, has been found in Lithium Forum 2017 Q1. This issue affects some unknown processing of the component Compose Message Handler. The manipulation of the argument upload_url leads to server-side request forgery. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.Show less
1Halo
1Halo
Jun 17, 2026
Jun 27, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Halo CMS v1.5.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the template remote download function.
1Parse Url Project
1Parse Url
Jun 17, 2026
Jun 27, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url prior to 7.0.0.
1Smackcoders
1Import All Pages, Post Types, Products, Orders, And Users As Xml & Csv
Jun 17, 2026
Jun 27, 2022
N/A· v4
7.2 HIGH· v3
6.0 MEDIUM· v2
The Import Export All WordPress Images, Users & Post Types WordPress plugin before 6.5.3 does not fully validate the file to be imported via an URL before making an HTTP request to it, which could allow high privilege us...Show more
The Import Export All WordPress Images, Users & Post Types WordPress plugin before 6.5.3 does not fully validate the file to be imported via an URL before making an HTTP request to it, which could allow high privilege users such as admin to perform Blind SSRF attacksShow less
1Ibm
1Jazz Team Server
Jun 17, 2026
Jun 24, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading...Show more
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 198931.Show less
1Ibm
1Jazz Team Server
Jun 17, 2026
Jun 24, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading...Show more
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.Show less
1Zhyd
1Oneblog
Jun 17, 2026
Jun 23, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Logo parameter under the Link module.
1Zhyd
1Oneblog
Jun 17, 2026
Jun 23, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the parameter entryUrls.
1Rangerstudio
1Directus
Jun 17, 2026
Jun 22, 2022
N/A· v4
5.0 MEDIUM· v3
4.0 MEDIUM· v2
In directus versions v9.0.0-beta.2 through 9.6.0 are vulnerable to server-side request forgery (SSRF) in the media upload functionality which allows a low privileged user to perform internal network port scans.
1Qlik
1Qlik Sense
Jun 17, 2026
Jun 21, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The GeoAnalytics feature in Qlik Sense April 2020 patch 4 allows SSRF.
1Tandoor
1Recipes
Jun 17, 2026
Jun 19, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In Recipes, versions 0.9.1 through 1.2.5 are vulnerable to Server Side Request Forgery (SSRF), in the “Import Recipe” functionality. When an attacker enters the localhost URL, a low privileged attacker can access/read th...Show more
In Recipes, versions 0.9.1 through 1.2.5 are vulnerable to Server Side Request Forgery (SSRF), in the “Import Recipe” functionality. When an attacker enters the localhost URL, a low privileged attacker can access/read the internal file system to access sensitive information.Show less
1Flatcore
1Flatcore Cms
Jun 17, 2026
Jun 15, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
flatCore-CMS version 2.0.8 calls dangerous functions, causing server-side request forgery vulnerabilities.
1Sap
2Host Agent
Netweaver Abap
Jun 17, 2026
Jun 14, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
SAP NetWeaver, ABAP Platform and SAP Host Agent - versions KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, 8.04, KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, 8.04, SAPHOSTAGENT 7.22, al...Show more
SAP NetWeaver, ABAP Platform and SAP Host Agent - versions KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, 8.04, KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, 8.04, SAPHOSTAGENT 7.22, allows an authenticated user to misuse a function of sapcontrol webfunctionality(startservice) in Kernel which enables malicious users to retrieve information. On successful exploitation, an attacker can obtain technical information like system number or physical address, which is otherwise restricted, causing a limited impact on the confidentiality of the application.Show less
1Invisioncommunity
1Ips Community Suite
Jun 17, 2026
Jun 13, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
A Server-Side Request Forgery (SSRF) vulnerability in IPS Community Suite before 4.6.2 allows remote authenticated users to request arbitrary URLs or trigger deserialization via phar protocol when generating class names...Show more
A Server-Side Request Forgery (SSRF) vulnerability in IPS Community Suite before 4.6.2 allows remote authenticated users to request arbitrary URLs or trigger deserialization via phar protocol when generating class names dynamically. In some cases an exploitation is possible by an unauthenticated user.Show less
1Sap
1Netweaver
Jun 17, 2026
Jun 13, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Some part of SAP NetWeaver (EP Web Page Composer) does not sufficiently validate an XML document accepted from an untrusted source, which allows an adversary to exploit unprotected XML parking at endpoints, and a possibi...Show more
Some part of SAP NetWeaver (EP Web Page Composer) does not sufficiently validate an XML document accepted from an untrusted source, which allows an adversary to exploit unprotected XML parking at endpoints, and a possibility to conduct SSRF attacks that could compromise system�s Availability by causing system to crash.Show less
1Apache
1Dubbo
Jun 17, 2026
Jun 9, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check which can cause open redirect or SSRF vulnerability.
1Baidu
1Kity Minder
Jun 17, 2026
Jun 9, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Kity Minder v1.3.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the init function at ImageCapture.class.php.
1Monstaftp
1Monstaftp
Jun 17, 2026
Jun 9, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
MonstaFTP v2.10.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the function performFetchRequest at HTTPFetcher.php.
1Jizhicms
1Jizhicms
Jun 17, 2026
Jun 9, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Jizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Index function in app/admin/c/PluginsController.php.
1Jizhicms
1Jizhicms
Jun 17, 2026
Jun 9, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Jizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Update function in app/admin/c/TemplateController.php.