← Back
CWE-918

3,430 CVEs • Abstraction: Base

Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

JSON object

Loading...

CVEs (3,430)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Bigbluebutton
1Bigbluebutton
Jun 17, 2026
Oct 21, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploaded Office document that has a crafted URL in an ODF xlink field.
1Sap
1Businessobjects Business Intelligence Platform
Jun 17, 2026
Oct 20, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which...Show more
SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which is otherwise not accessible externally. On successful exploitation, attacker can scan internal network to determine internal infrastructure and gather information for further attacks like remote file inclusion, retrieve server files, bypass firewall and force the vulnerable server to perform malicious requests, resulting in a Server-Side Request Forgery vulnerability.Show less
1Jetbrains
1Youtrack
Jun 17, 2026
Oct 19, 2020
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
In JetBrains YouTrack before 2020.2.10514, SSRF is possible because URL filtering can be escaped.
2Eclecticiq
Libtaxii Project
2Libtaxii
Opentaxii
Jun 17, 2026
Oct 17, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML par...Show more
TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method "wraps the lxml library" and that this may be an issue to "raise ... to the lxml group.Show less
1Emby
1Emby
Jun 17, 2026
Oct 10, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter.
1Node Pdf Generator Project
1Node Pdf Generator
Jun 17, 2026
Oct 6, 2020
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
This affects all versions of package node-pdf-generator. Due to lack of user input validation and sanitization done to the content given to node-pdf-generator, it is possible for an attacker to craft a url that will be p...Show more
This affects all versions of package node-pdf-generator. Due to lack of user input validation and sanitization done to the content given to node-pdf-generator, it is possible for an attacker to craft a url that will be passed to an external server allowing an SSRF attack.Show less
1Phantomjs Seo Project
1Phantomjs Seo
Jun 17, 2026
Oct 6, 2020
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
This affects all versions of package phantomjs-seo. It is possible for an attacker to craft a url that will be passed to a PhantomJS instance allowing for an SSRF attack.
1Teltonika Networks
1Trb245 Firmware
Jun 17, 2026
Oct 1, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Server-Side Request Forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a low privileged user to cause the application to perform HTTP GET requests to arbitrary URLs.
1Mbconnectline
2Mbconnect24
Mymbconnect24
Jun 17, 2026
Sep 30, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a CSRF issue (with resultant SSRF) in the com_mb24proxy module, allowing attackers to steal session information from logged...Show more
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a CSRF issue (with resultant SSRF) in the com_mb24proxy module, allowing attackers to steal session information from logged-in users with a crafted link.Show less
1Zohocorp
1Manageengine Application Control Plus
Jun 17, 2026
Sep 30, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An SSRF issue was discovered in Zoho Application Control Plus before version 10.0.511. The mail gateway configuration feature allows an attacker to perform a scan in order to discover open ports on a machine as well as a...Show more
An SSRF issue was discovered in Zoho Application Control Plus before version 10.0.511. The mail gateway configuration feature allows an attacker to perform a scan in order to discover open ports on a machine as well as available machines on the network segment on which the instance of the product is deployed.Show less
1Ozeki
1Ozeki Ng Sms Gateway
Jun 17, 2026
Sep 22, 2020
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Ozeki NG SMS Gateway through 4.17.6 allows SSRF via SMS WCF or RSS To SMS.
1Acronis
1Cyber Backup
Jun 17, 2026
Sep 21, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
An issue was discovered in Acronis Cyber Backup before 12.5 Build 16342. Some API endpoints on port 9877 under /api/ams/ accept an additional custom Shard header. The value of this header is afterwards used in a separate...Show more
An issue was discovered in Acronis Cyber Backup before 12.5 Build 16342. Some API endpoints on port 9877 under /api/ams/ accept an additional custom Shard header. The value of this header is afterwards used in a separate web request issued by the application itself. This can be abused to conduct SSRF attacks against otherwise unreachable Acronis services that are bound to localhost such as the NotificationService on 127.0.0.1:30572.Show less
1Gradle
1Enterprise
Jun 17, 2026
Sep 18, 2020
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in Gradle Enterprise 2018.5 - 2020.2.4. When configuring Gradle Enterprise to integrate with a SAML identity provider, an XML metadata file can be uploaded by an administrator. The server side pro...Show more
An issue was discovered in Gradle Enterprise 2018.5 - 2020.2.4. When configuring Gradle Enterprise to integrate with a SAML identity provider, an XML metadata file can be uploaded by an administrator. The server side processing of this file dereferences XML External Entities (XXE), allowing a remote attacker with administrative access to perform server side request forgery.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Sep 14, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a blind SSRF attack through the repository mirroring feature.
1Ibm
1Infosphere Metadata Asset Manager
Jun 17, 2026
Sep 4, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM InfoSphere Metadata Asset Manager 11.7 is vulnerable to server-side request forgery. By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to submit or control serve...Show more
IBM InfoSphere Metadata Asset Manager 11.7 is vulnerable to server-side request forgery. By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to submit or control server requests. IBM X-Force ID: 185416.Show less
1Open Xchange
1Open Xchange Appsuite
Jun 17, 2026
Aug 31, 2020
N/A· v4
5.0 MEDIUM· v3
4.0 MEDIUM· v2
OX App Suite 7.10.3 and earlier allows SSRF, related to the mail account API and the /folder/list API.
1Stiltsoft
1Table Filter And Charts For Confluence Server
Jun 17, 2026
Aug 29, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The Table Filter and Charts for Confluence Server app before 5.3.26 (for Atlassian Confluence) allows SSRF via the "Table from CSV" macro (URL parameter).
1Spinnaker
1Orca
Jun 17, 2026
Aug 28, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Spinnaker template resolution functionality is vulnerable to Server-Side Request Forgery (SSRF), which allows an attacker to send requests on behalf of Spinnaker potentially leading to sensitive data disclosure.
1Ericom
1Access Server
Jun 17, 2026
Aug 26, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Ericom Access Server 9.2.0 (for AccessNow and Ericom Blaze) allows SSRF to make outbound WebSocket connection requests on arbitrary TCP ports, and provides "Cannot connect to" error messages to inform the attacker about...Show more
Ericom Access Server 9.2.0 (for AccessNow and Ericom Blaze) allows SSRF to make outbound WebSocket connection requests on arbitrary TCP ports, and provides "Cannot connect to" error messages to inform the attacker about closed ports.Show less
1Cellopoint
1Cellos
Jun 17, 2026
Aug 25, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly. With cookie of an authenticated user, attackers can temper with the URL parameter and access arbitrary file on system.