CWE-918
3,430 CVEs • Abstraction: Base
Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
CVEs (3,430)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Concrete CMS (formerly concrete5) versions 8.5.6 and below and version 9.0.0 allow local IP importing causing the system to be vulnerable toa. SSRF attacks on the private LAN servers by reading files from the local LAN....Show more |
Concrete CMS (formerly concrete5) versions below 8.5.7 has a SSRF mitigation bypass using DNS Rebind attack giving an attacker the ability to fetch cloud IAAS (ex AWS) IAM keys.To fix this Concrete CMS no longer allows d...Show more |
The server in Jamf Pro before 10.32.0 has an SSRF vulnerability, aka PI-006352. NOTE: Jamf Nation will also publish an article about this vulnerability. |
An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension before 1.0.6 for TYPO3. The extension fails to restrict the image download to the configured pixx.io DAM URL, resulting in SSRF. As a resul...Show more |
1Sonatype 1Nexus Repository Manager Jun 17, 2026 Nov 4, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Sonatype Nexus Repository Manager 3.x before 3.36.0 allows a remote authenticated attacker to potentially perform network enumeration via Server Side Request Forgery (SSRF). |
1Ibm 1Infosphere Information Server Jun 17, 2026 Nov 2, 2021 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 IBM InfoSphere Data Flow Designer (IBM InfoSphere Information Server 11.7 ) is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, pot...Show more |
1Ibm 7Engineering Lifecycle Optimization Engineering Requirements Quality Assistant On PremisesEngineering Workflow Management+4 moreJun 17, 2026 Oct 27, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 IBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or fac...Show more |
1Zohocorp 1Manageengine Applications Manager Jun 17, 2026 Oct 21, 2021 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 An SSRF issue was discovered in Zoho ManageEngine Applications Manager build 15200. |
1Alfresco 2Alfresco Content Services Alfresco Transform ServicesJun 17, 2026 Oct 21, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in Hyland org.alfresco:alfresco-content-services through 6.2.2.18 and org.alfresco:alfresco-transform-services through 1.3. A crafted HTML file, once uploaded, could trigger an unexpected request...Show more |
In Camaleon CMS, versions 2.1.2.0 to 2.6.0, are vulnerable to Server-Side Request Forgery (SSRF) in the media upload feature, which allows admin users to fetch media files from external URLs but fails to validate URLs re...Show more |
iTop is an open source web based IT Service Management tool. In affected versions an attacker can call the system setup without authentication. Given specific parameters this can lead to SSRF. This issue has been resolve...Show more |
1Vmware 3Cloud Foundation Vrealize OperationsVrealize Suite Lifecycle ManagerJun 17, 2026 Oct 13, 2021 N/A· v4 2.7 LOW· v3 4.0 MEDIUM· v2 Releases prior to VMware vRealize Operations 8.6 contain a Server Side Request Forgery (SSRF) vulnerability. |
An issue was discovered in Zammad before 4.1.1. SSRF can occur via GitHub or GitLab integration. |
A Server-Side Request Forgery vulnerability was found in concrete5 < 8.5.5 that allowed a decimal notation encoded IP address to bypass the limitations in place for localhost allowing interaction with local services. Imp...Show more |
Myucms v2.2.1 contains a server-side request forgery (SSRF) in the component \controller\index.php, which can be exploited via the sj() method. |
Myucms v2.2.1 contains a server-side request forgery (SSRF) in the component \controller\index.php, which can be exploited via the sql() method. |
In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be used by attackers to exploit Server Side Request Forgery attacks. |
In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks. |
Nagios Enterprises NagiosXI <= 5.8.4 contains a Server-Side Request Forgery (SSRF) vulnerability in schedulereport.php. Any authenticated user can create scheduled reports containing PDF screenshots of any view in the Na...Show more |
There is a server-side request forgery vulnerability in HUAWEI P40 versions 10.1.0.118(C00E116R3P3). This vulnerability is due to insufficient validation of parameters while dealing with some messages. A successful explo...Show more |