← Back
CWE-918

3,430 CVEs • Abstraction: Base

Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

JSON object

Loading...

CVEs (3,430)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Canto
1Canto
Jun 17, 2026
Nov 30, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/detail.php?subdomain=SSRF.
1Microstrategy
1Microstrategy
Jul 9, 2026
Nov 24, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A Server-Side Request Forgery (SSRF) affecting the PDF generation in MicroStrategy 10.4, 2019 before Update 6, and 2020 before Update 2 allows authenticated users to access the content of internal network resources or le...Show more
A Server-Side Request Forgery (SSRF) affecting the PDF generation in MicroStrategy 10.4, 2019 before Update 6, and 2020 before Update 2 allows authenticated users to access the content of internal network resources or leak files from the local system via HTML containers embedded in a dossier/dashboard document. NOTE: 10.4., no fix will be released as version will reach end-of-life on 31/12/2020.Show less
1Private Ip Project
1Private Ip
Jun 17, 2026
Nov 23, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Insufficient RegEx in private-ip npm package v1.0.5 and below insufficiently filters reserved IP ranges resulting in indeterminate SSRF. An attacker can perform a large range of requests to ARIN reserved IP ranges, resul...Show more
Insufficient RegEx in private-ip npm package v1.0.5 and below insufficiently filters reserved IP ranges resulting in indeterminate SSRF. An attacker can perform a large range of requests to ARIN reserved IP ranges, resulting in an indeterminable number of critical attack vectors, allowing remote attackers to request server-side resources or potentially execute arbitrary code through various SSRF techniques.Show less
1Jetbrains
1Youtrack
Jun 17, 2026
Nov 16, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
JetBrains YouTrack before 2020.3.5333 was vulnerable to SSRF.
1Jetbrains
1Youtrack
Jun 17, 2026
Nov 16, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
JetBrains YouTrack before 2020.3.888 was vulnerable to SSRF.
2Apache
Oracle
18Api Gateway
BatikBusiness Intelligence+15 more
Jun 17, 2026
Nov 12, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause...Show more
Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.Show less
1Mcafee
1Mvision Endpoint
Jun 17, 2026
Nov 11, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Server-side request forgery vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers trigger server-side DNS requests to arbitrary domains via carefully constructed XML files l...Show more
Server-side request forgery vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers trigger server-side DNS requests to arbitrary domains via carefully constructed XML files loaded by an ePO administrator.Show less
1Mcafee
1Mvision Endpoint
Jun 17, 2026
Nov 11, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
External entity attack vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers to gain control of a resource or trigger arbitrary code execution via improper input validation...Show more
External entity attack vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers to gain control of a resource or trigger arbitrary code execution via improper input validation of an HTTP request, where the content for the attack has been loaded into ePO by an ePO administrator.Show less
1Canto
1Canto
Jun 17, 2026
Nov 10, 2020
N/A· v4
7.2 HIGH· v3
5.0 MEDIUM· v2
The Canto plugin 1.3.0 for WordPress allows includes/lib/download.php?subdomain= SSRF.
1Sap
1Fiori Launchpad (news Tile Application)
Jun 17, 2026
Nov 10, 2020
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to send a crafted request to a vulnerable web application. It is usually used to target internal systems be...Show more
SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to send a crafted request to a vulnerable web application. It is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network to retrieve sensitive / confidential resources which are otherwise restricted for internal usage only, resulting in a Server-Side Request Forgery vulnerability.Show less
1Sap
1Commerce Cloud (accelerator Payment Mock)
Jun 17, 2026
Nov 10, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to submit a crafted request over a network to a particular SAP Commerce module URL which will be proces...Show more
SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to submit a crafted request over a network to a particular SAP Commerce module URL which will be processed without further interaction, the crafted request leads to Server Side Request Forgery attack which could lead to retrieval of limited pieces of information about the service with no impact on integrity or availability.Show less
1Trendmicro
1Interscan Messaging Security Virtual Appliance
Jun 17, 2026
Nov 9, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to a server side request forgery vulnerability which could allow an authenticated attacker to abuse the product's web server and grant...Show more
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to a server side request forgery vulnerability which could allow an authenticated attacker to abuse the product's web server and grant access to web resources or parts of local files. An attacker must already have obtained authenticated privileges on the product to exploit this vulnerability.Show less
1Bitdefender
1Update Server
Jun 17, 2026
Nov 9, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Insufficient validation in the Bitdefender Update Server and BEST Relay components of Bitdefender Endpoint Security Tools versions prior to 6.6.20.294 allows an unprivileged attacker to bypass the in-place mitigations an...Show more
Insufficient validation in the Bitdefender Update Server and BEST Relay components of Bitdefender Endpoint Security Tools versions prior to 6.6.20.294 allows an unprivileged attacker to bypass the in-place mitigations and interact with hosts on the network. This issue affects: Bitdefender Update Server versions prior to 6.6.20.294.Show less
2Axios
Siemens
2Axios
Sinec Ins
Jun 17, 2026
Nov 6, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.
2Misp
Misp Project
2Misp
Misp
Jun 22, 2026
Nov 2, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
MISP through 2.4.133 allows SSRF in the REST client via the use_full_path parameter with an arbitrary URL.
2Enhancesoft
Osticket
2Osticket
Osticket
Jul 10, 2026
Nov 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.
1Getgophish
1Gophish
Jun 17, 2026
Oct 28, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Gophish before 0.11.0 allows SSRF attacks.
1Arubanetworks
1Airwave Glass
Jun 17, 2026
Oct 26, 2020
N/A· v4
5.8 MEDIUM· v3
5.0 MEDIUM· v2
A remote server-side request forgery (ssrf) vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
1Crmeb
1Crmeb
Jul 9, 2026
Oct 23, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.
1Open Xchange
1Open Xchange Appsuite
Jun 17, 2026
Oct 23, 2020
N/A· v4
5.0 MEDIUM· v3
4.0 MEDIUM· v2
OX App Suite through 7.10.3 allows SSRF via the the /ajax/messaging/message message API.